Description
** DISPUTED ** The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x.
Remediation
References
Related Vulnerabilities
WordPress 6.0.x Multiple Vulnerabilities (6.0 - 6.0.8)
ownCloud Other Vulnerability (CVE-2014-2056)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-21014)
Joomla! Core 1.0.x Multiple Unspecified Vulnerabilities (1.0.0 - 1.0.7)
WordPress Plugin Image Metadata Cruncher Multiple Vulnerabilities (1.8)