CVE-2015-20107

🟡 Monitoruj

W module mailcap w Pythonie możliwe jest wstrzyknięcie poleceń powłoki przez niezweryfikowane dane.

CVSS
7.6
EPSS
7.1%
Exploit
poc
Vendor
netapp
Opis źródłowy (NVD)

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.6
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)7.1%
Opublikowano (NVD)2022-04-13 16:15:08 UTC
Ostatnia modyfikacja (NVD)2026-10-08 01:16:30 UTC
Referencje