CVE-2011-4940: Python
Low severity, CVSS 2.6. EPSS: 3.2% chance of exploitation in the next 30 days.
The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.
Affected products
- Python Python: up to and including 2.5.6; version 0.9.0 only; version 0.9.1 only; version 1.2 only; version 1.3 only; version 1.5.2 only; …
Published 2012-06-27. Last modified 2026-06-16.