Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
BID:54083
Info
Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
| Bugtraq ID: | 54083 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4940 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2012 12:00AM |
| Updated: | Nov 16 2012 03:40PM |
| Credit: | Vendor |
| Vulnerable: |
VMWare ESX Server 4.1 VMWare ESX Server 4.0 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Python Software Foundation Python 2.6.5 Python Software Foundation Python 2.6.2 Python Software Foundation Python 2.5.5 Python Software Foundation Python 2.5.3 Python Software Foundation Python 2.5.2 -r6 Python Software Foundation Python 2.5.2 Python Software Foundation Python 2.5.1 Python Software Foundation Python 2.5.5c2 Python Software Foundation Python 2.5 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Avaya Aura Experience Portal 6.0 |
| Not Vulnerable: | |
Discussion
Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
Python is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Python is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Python SimpleHTTPServer 'list_directory()' Function Cross Site Scripting Vulnerability
References:
References:
- Python Homepage (Python Software Foundation)