这是indexloc提供的服务,不要输入任何密码
Skip to content

This application is vulnerable #25

@ChiChou

Description

@ChiChou

There's a easy exploiting vulnerability in:
https://github.com/humitos/pyfispot/blob/master/raspberrypi/home/pi/apps/pyfispot/main.py#L69

A fake X-Real-IP header will execute arbitrary command on the server

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions