CVE-2002-0131
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/03/2002
Last modified:
03/04/2025
Description
ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:activestate:activepython:*:*:*:*:*:*:*:* | ||
cpe:2.3:a:activestate:activepython:2.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?t=101113015900001&r=1&w=2
- http://www.iss.net/security_center/static/7910.php
- http://www.securityfocus.com/archive/1/250814
- http://www.securityfocus.com/bid/3893
- http://marc.info/?t=101113015900001&r=1&w=2
- http://www.iss.net/security_center/static/7910.php
- http://www.securityfocus.com/archive/1/250814
- http://www.securityfocus.com/bid/3893