Pyscript

PyScript Pentesting Guide

PyScript is a new framework developed for integrating Python into HTML so, it can be used alongside HTML. In this cheat sheet, you'll find how to use PyScript for your penetration testing purposes.

Dumping / Retrieving files from the Emscripten virtual memory filesystem:

CVE ID: CVE-2022-30286 Code:

<py-script>
        with open('/lib/python3.10/site-packages/_pyodide/_base.py', 'r') as fin:
        out = fin.read()
        print(out)
</py-script>

Result:

CVE ID: CVE-2022-30286 Code:

Result:

Cross Site Scripting (Ordinary)

Code:

Result:

Cross Site Scripting (Python Obfuscated)

Code:

Result:

Cross Site Scripting (JavaScript Obfuscation)

Code:

Result:

DoS attack (Infinity loop)

Code:

Result:

Last updated