Arbitrary Code Execution in Tofu 0.2 via Crafted Pickled Objects

Arbitrary Code Execution in Tofu 0.2 via Crafted Pickled Objects

CVE-2005-3008 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes.

Learn more about our Web Application Penetration Testing UK.