Miss Islington (bot)
148 exploits
Active since Jun 2019
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVSS 7.5
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CPython < 3.15.0a6 - Command Injection via IMAP Command Newline Injection
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
Incomplete control character validation in http.cookies
CVSS 7.5
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
tarfile extraction filter bypass allows escaping the destination directory
Python Software Foundation CPython - Tarfile.extract() Doesn't Fully Respect Filter Parameter
CVSS 5.3
Configuration Injection via Carriage Return (\r) in write() method
Configuration Injection via Carriage Return (\r) in write() method
tarfile extraction filter bypass allows escaping the destination directory
Configuration Injection via Carriage Return (\r) in write() method
tarfile extraction filter bypass allows escaping the destination directory
tarfile extraction filter bypass allows escaping the destination directory
CPython >3.11 Insecure Input Validation resulting in privilege escalation
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
tarfile.data_filter path traversal bypass allows writing outside the extraction directory