Skip to content
Appaloosa Scout

Vulnerability · NVD

CVE-2014-4650

CRITICAL 9.8

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS 24.70% moderate exploit risk percentile 97.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

Vulnerable CPE configurations (4)
Vendor Product Versions
python python
All platforms (wildcard)
≥2.7.0 <2.7.8
python python
All platforms (wildcard)
≥3.2.0 <3.2.6
python python
All platforms (wildcard)
≥3.3.0 <3.3.6
python python
All platforms (wildcard)
≥3.4.0 <3.4.2
View on NVD ↗ Advisory · bugs.python.org