peter bassill · operator
$ cve CVE-2014-4650 JSON

CVE-2014-4650 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 24.7% (pctl 98)

Patch early

A public exploit exists.

Description

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS24.7% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2020-02-20
Last modified2026-06-17

Affected (3)

VendorProduct
pythonpython
redhatenterprise linux
redhatsoftware collections

Public exploits

SourceTitleDate
exploit-dbPython CGIHTTPServer - Encoded Directory Traversal2014-06-27

References

→ the Explorer  ·  watch your stack  ·  NVD