The python script "host.py" allows for arbitrary file upload!
Although there is some checking it can be easily bypassed to upload a file anywhere on your system!
And since it has to be run as root for the port 443 to be usable A REMOTE ACTOR CAN REPLACE ANY FILE OF YOUR SERVER AS ROOT, LEADING TO FULL SYSTEM TAKEOVER!
I won't go into any more details but it's easily, easily exploitable. Please remove the upload functionality from the script.
The python script "host.py" allows for arbitrary file upload!
Although there is some checking it can be easily bypassed to upload a file anywhere on your system!
And since it has to be run as root for the port 443 to be usable A REMOTE ACTOR CAN REPLACE ANY FILE OF YOUR SERVER AS ROOT, LEADING TO FULL SYSTEM TAKEOVER!
I won't go into any more details but it's easily, easily exploitable. Please remove the upload functionality from the script.