Other nomination
Memcached Command Injections at Pylibmc
Flask-Session builds its memcached key by concatenating a prefix with the session cookie value, so CRLF smuggled in through octal-quoted cookie escapes injects raw memcached commands. An attacker can store an arbitrary pickle under a chosen key and then load it as their own session, gaining remote code execution when the library unpickles it.
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.