cpython是Python基金会的用C语言实现的Python解释器。 cpython 存在环境问题漏洞,攻击者可利用该漏洞可以使用分号(;)分隔查询参数,导致恶意请求被缓存为完全安全的请求。以下产品及版本受到影响:before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | python/cpython | 0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23337 | 7.2 HIGH | Command Injection |
| CVE-2021-23338 | 6.6 MEDIUM | Deserialization of Untrusted Data |
| CVE-2020-28500 | 5.3 MEDIUM | Regular Expression Denial of Service (ReDoS) |
| CVE-2020-24899 | Nagios XI和Nagios 命令注入漏洞 | |
| CVE-2021-26822 | Teachers Record Management System SQL注入漏洞 | |
| CVE-2020-35734 | Batflat 注入漏洞 | |
| CVE-2021-26201 | CASAP Automated Enrollment SQL注入漏洞 | |
| CVE-2021-26200 | SourceCodester user area for Library System SQL注入漏洞 | |
| CVE-2021-3239 | Sourcecodester Pisay Online E-Learning System SQL注入漏洞 | |
| CVE-2020-29143 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29139 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29140 | OpenEMR SQL注入漏洞 | |
| CVE-2020-29142 | OpenEMR SQL注入漏洞 | |
| CVE-2020-28337 | Microweber 路径遍历漏洞 | |
| CVE-2021-27211 | Steghide 安全漏洞 | |
| CVE-2021-27201 | Endian Firewall Community 操作系统命令注入漏洞 | |
| CVE-2021-3375 | Atomi ActivePresenter 缓冲区错误漏洞 | |
| CVE-2021-25296 | Nagios XI 安全漏洞 | |
| CVE-2020-22427 | Nagios XI 代码注入漏洞 | |
| CVE-2020-22425 | Centreon SQL注入漏洞 |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet