Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-17522

EPSS 0.65% · P71
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-17522

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that exploitation is impossible because the code relies on subprocess.Popen and the default shell=False setting
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Python 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Python是Python软件基金会的一套开源的、面向对象的程序设计语言。该语言具有可扩展、支持模块和包、支持多种平台等特点。 Python 3.6.3及之前的版本中的Lib/webbrowser.py文件存在安全漏洞,该漏洞源于程序在启动程序之前,没有验证字符串。远程攻击者可借助特制的URL利用该漏洞实施参数注入攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-17522

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-17522

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-12-14 · 32 CVEs total

CVE-2017-17527PasDoc 安全漏洞
CVE-2017-17672vBulletin 安全漏洞
CVE-2017-17671vBulletin for Windows 安全漏洞
CVE-2017-17684Panda Global Protection 安全漏洞
CVE-2017-17683Panda Global Protection 安全漏洞
CVE-2017-17682ImageMagick 资源管理错误漏洞
CVE-2017-17681ImageMagick 安全漏洞
CVE-2017-17680ImageMagick 安全漏洞
CVE-2017-17535Bob Hepple gjots2 安全漏洞
CVE-2017-17534Mensis 安全漏洞
CVE-2017-17533Tkabber 安全漏洞
CVE-2017-17532Kiwi 安全漏洞
CVE-2017-17531GNU GLOBAL 安全漏洞
CVE-2017-17530Geomview 注入漏洞
CVE-2017-17529AbiWord 安全漏洞
CVE-2017-17528ScummVM 安全漏洞
CVE-2017-16355Phusion Passenger 安全漏洞
CVE-2017-17526Bernard Parisse Giac 安全漏洞
CVE-2017-17525xTuple PostBooks 安全漏洞
CVE-2017-17524SWI-Prolog 安全漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-17522

No comments yet


Leave a comment