We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
There's a easy exploiting vulnerability in: https://github.com/humitos/pyfispot/blob/master/raspberrypi/home/pi/apps/pyfispot/main.py#L69
A fake X-Real-IP header will execute arbitrary command on the server
X-Real-IP
The text was updated successfully, but these errors were encountered:
Thanks for your report. You are right.
We will need to validate that the request.remote_addr is a valid IP. Maybe with a regex? Would you like to propose a PR for this?
request.remote_addr
Sorry, something went wrong.
No branches or pull requests
There's a easy exploiting vulnerability in:
https://github.com/humitos/pyfispot/blob/master/raspberrypi/home/pi/apps/pyfispot/main.py#L69
A fake
X-Real-IP
header will execute arbitrary command on the serverThe text was updated successfully, but these errors were encountered: