Files
CVEs-PoC/2008/CVE-2008-5983.md
T
2025-09-29 21:09:30 +02:00

851 B

CVE-2008-5983

Description

Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.

POC

Reference

Github

No PoCs found on GitHub currently.