Web Hack List

Other nomination

Memcached Command Injections at Pylibmc

Flask-Session builds its memcached key by concatenating a prefix with the session cookie value, so CRLF smuggled in through octal-quoted cookie escapes injects raw memcached commands. An attacker can store an arbitrary pickle under a chosen key and then load it as their own session, gaining remote code execution when the library unpickles it.

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.