CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. Its EPSS score suggests a 24.7% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2014-4650
Severity
CRITICAL
CVSS
9.8
EPSS
24.70%
Original NVD Description
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
Related CVEs
Other vulnerabilities affecting the same vendor(s)