CVE

Exploiting an Arbitrary File Write via MIME Type Misparsing

Exploiting an Arbitrary File Write via MIME Type Misparsing

A while back while going through my files, I came across FLB-Music-Player, which I was using a while back before switching to a self-hosted alternative called Navidrome, which I run on my raspberry pi. I decided to take a look at it from a security point of view to try and identify any vulnerabilities in it. This blogpost will be a walkthrough of an interesting vulnerability I found in FLB-Music-Player 1.2.1, that could be abused to achieve RCE.

Read More