logo

White-box penetration testing: Debugging for Python vulnerabilities

ID: b60cca60-b585-5e67-ba4c-554d208bb325

STIX ID: report--b60cca60-b585-5e67-ba4c-554d208bb325

Feed Name: YesWeHack Blog

Threat Score
55/100

Date Published: 2024-09-12

Date Updated: 2026-07-15

...
...

This article demonstrates a white‑box penetration test against a Dockerized Python Flask application vulnerable to server‑side template injection (SSTI). It covers setting up debugpy and VS Code remote debugging, includes the vulnerable application and Docker configuration, shows PoC Jinja2 payloads that yield RCE despite HTML escaping (including techniques to construct strings without quotes), and discusses related CWE categories and testing takeaways.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.