CVE-2013-1630
pyshop < 0.7.1 - Remote Code Execution via Unverified HTTP Package Download
Title source: llmDescription
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a/
Patch x_refsource_confirm
https://github.com/mardiros/pyshop/commit/ffadb0bcdef1e385884571670210cfd6ba351784
Various Sources x_refsource_confirm
https://github.com/mardiros/pyshop/blob/master/CHANGES.txt
Scores
EPSS
0.0208
EPSS Percentile
79.2%
Details
CWE
CWE-20
Status
published
Products (8)
guillaume_gauvrit/pyshop
0.1
guillaume_gauvrit/pyshop
0.2
guillaume_gauvrit/pyshop
0.3
guillaume_gauvrit/pyshop
0.4
guillaume_gauvrit/pyshop
0.5
guillaume_gauvrit/pyshop
0.6
guillaume_gauvrit/pyshop
< 0.7
pypi/pyshop
0 - 0.7.1PyPI
Published
Aug 06, 2013
Tracked Since
Feb 18, 2026