CVE-2011-4940Cross-site Scripting in Python

CWE-79Cross-site Scripting15 documents8 sources
Severity
2.6LOWNVD
EPSS
0.3%
top 49.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 13

Description

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages4 packages

debiandebian/python2.7< python2.7 2.7.2-8 (bullseye)
NVDpython/python2.5.6+37

🔴Vulnerability Details

2
GHSA
GHSA-cr6h-6cqx-mw3f: The list_directory function in Lib/SimpleHTTPServer2022-05-13
OSV
CVE-2011-4940: The list_directory function in Lib/SimpleHTTPServer2012-06-27

📋Vendor Advisories

7
VMware
VMware security updates for vSphere API and ESX Service Console2012-11-15
Ubuntu
Python 2.5 vulnerabilities2012-10-17
Ubuntu
Python 2.4 vulnerabilities2012-10-17
Ubuntu
Python 2.6 vulnerabilities2012-10-04
Ubuntu
Python 2.7 vulnerabilities2012-10-02

💬Community

5
Bugzilla
CVE-2012-2639 python (SimpleHTTPServer): XSS attacks against Internet Explorer 7 via UTF-7 encoding2012-06-26
Bugzilla
CVE-2011-4940 CVE-2011-4944 python26 various flaws [epel-5]2012-03-30
Bugzilla
CVE-2011-4940 CVE-2012-0845 CVE-2011-4944 python3 various flaws [fedora-all]2012-03-30
Bugzilla
CVE-2011-4940 CVE-2012-0845 CVE-2011-4944 python various flaws [fedora-all]2012-03-30
Bugzilla
CVE-2011-4940 python: potential XSS in SimpleHTTPServer's list_directory()2012-03-14
CVE-2011-4940 — Cross-site Scripting in Python | cvebase