CVE-2013-1630
06.08.2013, 02:52
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.Enginsight
Vendor | Product | Version |
---|---|---|
guillaume_gauvrit | pyshop | 𝑥 ≤ 0.7 |
guillaume_gauvrit | pyshop | 0.1 |
guillaume_gauvrit | pyshop | 0.2 |
guillaume_gauvrit | pyshop | 0.3 |
guillaume_gauvrit | pyshop | 0.4 |
guillaume_gauvrit | pyshop | 0.5 |
guillaume_gauvrit | pyshop | 0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References