National Cyber Warfare Foundation (NCWF) Forums


New Python URL Parsing Flaw Could Enable Command Execution Attacks


0 user ratings
2023-08-20 16:00:42
milo
Attacks

 - archive -- 
A high-severity security flaw has been disclosed in the Python URL parsing function that could be exploited to bypass domain or protocol filtering methods implemented with a blocklist, ultimately resulting in arbitrary file reads and command execution.
"urlparse has a parsing problem when the entire URL starts with blank characters," the CERT Coordination Center (CERT/CC) said in a Friday



Source: TheHackerNews
Source Link: https://thehackernews.com/2023/08/new-python-url-parsing-flaw-enables.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.