ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?t=101113015900001&r=1&w=2 - | |
References | () http://www.iss.net/security_center/static/7910.php - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/250814 - | |
References | () http://www.securityfocus.com/bid/3893 - |
Information
Published : 2002-03-25 05:00
Updated : 2024-11-20 23:38
NVD link : CVE-2002-0131
Mitre link : CVE-2002-0131
CVE.ORG link : CVE-2002-0131
JSON object : View
Products Affected
activestate
- activepython
CWE