Collected research
A New Vector For “Dirty” Arbitrary File Write to RCE
uWSGI parses any file that contains a uwsgi section header as a configuration file, and its exec magic variable runs a shell command while doing so. An attacker with only partial control of written file contents, here a PDF export carrying the payload in an image's EXIF metadata, can overwrite a .ini config and reach remote code execution, with the py-auto-reload option supplying the reload.
Record
- Researcher
- Maxence Schmitt and Lorenzo Stella
- Published by
- blog.doyensec.com
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Maxence Schmitt and Lorenzo Stella, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .