2.6
CVSSv2

CVE-2011-4940

Published: 27/06/2012 Updated: 13/02/2023
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python prior to 2.5.6c1, 2.6.x prior to 2.6.7 rc2, and 2.7.x prior to 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python python 2.4.2

python python 2.5.1

python python 2.3.4

python python 2.0.1

python python 2.3.1

python python 0.9.1

python python 2.1.2

python python 0.9.0

python python 1.6.1

python python 2.2.1

python python 2.5.4

python python 1.3

python python 2.2.2

python python 2.1.1

python python 1.5.2

python python 2.3.3

python python 2.3.2

python python 1.6

python python 1.2

python python 2.4.6

python python 2.2.3

python python 2.5.2

python python 2.3.7

python python

python python 2.5.3

python python 2.4.4

python python 2.3.5

python python 2.1.3

python python 2.4.1

python python 2.4.3

python python 2.6.6

python python 2.6.1

python python 2.6.3

python python 2.6.4

python python 2.6.2

python python 2.6.5

python python 2.7.1

python python 2.7.2

Vendor Advisories

Debian Bug report logs - #664135 [CVE-2011-4940] python: potential XSS in SimpleHTTPServer's list_directory() Package: python26; Maintainer for python26 is (unknown); Reported by: Luciano Bello <luciano@debianorg> Date: Thu, 15 Mar 2012 19:42:01 UTC Severity: important Tags: patch, security Fixed in version 267-1 Do ...
Synopsis Moderate: python security update Type/Severity Security Advisory: Moderate Topic Updated python packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Synopsis Moderate: python security update Type/Severity Security Advisory: Moderate Topic Updated python packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Several security issues were fixed in Python 27 ...
Several security issues were fixed in Python 24 ...
Several security issues were fixed in Python 25 ...
Several security issues were fixed in Python 26 ...
A denial of service flaw was found in the implementation of associative arrays (dictionaries) in Python An attacker able to supply a large number of inputs to a Python application (such as HTTP POST request parameters sent to a web application) that are used as keys when inserting data into an array could trigger multiple hash function collisions, ...