ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/250814 | mailing list |
http://marc.info/?t=101113015900001&r=1&w=2 | mailing list |
http://www.securityfocus.com/bid/3893 | vdb entry |
http://www.iss.net/security_center/static/7910.php | vdb entry vendor advisory |