CVE-2005-0089

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instan… (CVE-2005-0089)

Description

The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.

Source: CVELISTV5NVD

Metrics

Severity
none
no public PoC known
92.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
6.0 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2005-02-06 05:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • python

    python2.3.5

  • python

    python

References & sources

IDCVE-2005-0089