CVE-2016-1000110

Source
https://cve.org/CVERecord?id=CVE-2016-1000110
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1000110.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-1000110
Aliases
Downstream
Related
Published
2019-11-27T17:15:14.090Z
Modified
2026-02-24T07:51:41.610980Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.

References

Affected packages

Git / github.com/python/cpython

Affected ranges

Affected versions

3.*
3.2
v3.*
v3.4.4
v3.4.4rc1
v3.4.5
v3.4.5rc1
v3.5.0
v3.5.1
v3.5.1rc1
v3.5.2
v3.5.2rc1
v3.5.3rc1
v3.6.0a1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1000110.json"