A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://python-security.readthedocs.io/vuln/docxmlrpcserver-xss.html below:

Reflected XSS in DocXMLRPCServer — Python Security 0.0 documentation

Reflected XSS in DocXMLRPCServer

DocXMLRPCServer does not escape the server title.

The attacker has to find a way to control the server title.

Dates:

Fixed In Python issue

[security][CVE-2019-16935] A reflected XSS in python/Lib/DocXMLRPCServer.py.

CVE-2019-16935

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.

Timeline

Timeline using the disclosure date 2019-09-21 as reference:


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4