Lucene search

K

Pythonpaste Security Vulnerabilities

cve
cve

CVE-2010-2477

Multiple cross-site scripting (XSS) vulnerabilities in the paste.httpexceptions implementation in Paste before 1.7.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving a 404 status code, related to (1) paste.urlparser.StaticURLParser, (2) paste.urlparser.PkgResource...

5.6AI Score

0.003EPSS

2010-11-06 12:00 AM
31
cve
cve

CVE-2012-0878

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

6.4AI Score

0.045EPSS

2012-05-01 07:55 PM
27