Web Hack List

Collected research

A New Vector For “Dirty” Arbitrary File Write to RCE

uWSGI parses any file that contains a uwsgi section header as a configuration file, and its exec magic variable runs a shell command while doing so. An attacker with only partial control of written file contents, here a PDF export carrying the payload in an image's EXIF metadata, can overwrite a .ini config and reach remote code execution, with the py-auto-reload option supplying the reload.

Record

Researcher
Maxence Schmitt and Lorenzo Stella
Published by
blog.doyensec.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Maxence Schmitt and Lorenzo Stella, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .