跳转到帖子

pyLoad js2py Python Execution

recommended_posts

发布于
  • Members

pyLoad js2py Python Execution

Disclosed
01/13/2023
Created
02/22/2023

Description

pyLoad versions prior to 0.5.0b3.dev31 are vulnerable to Python code injection due to the pyimport functionality exposed through the js2py library. An unauthenticated attacker can issue a crafted POST request to the flash/addcrypted2 endpoint to leverage this for code execution. pyLoad by default runs two services, the primary of which is on port 8000 and can not be used by external hosts. A secondary "Click 'N' Load" service runs on port 9666 and can be used remotely without authentication.

Author(s)

  • Spencer McIntyre
  • bAu

Platform

Linux,Python,Unix

Architectures

cmd, x86, x64, python

Development

  • Source Code
  • History
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…