漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code. NOTE: Multiple third parties have disputed this issue and stated that it is not a security flaw in python-future and is a documented feature of Python’s import system in the handling of sys.path.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
python-future 安全漏洞
Vulnerability Description
python-future是Python Charmers开源的一个Python兼容软件。 Python-Future 1.0.0版本存在安全漏洞,该漏洞源于自动导入test.py文件,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A