don't expose path of Python

Disclosed: 2016-05-13 20:49:41 By tbehroz To gratipay
None
Vulnerability Details
Hello Team, While testing the web application I've found that if you enter the 3 or more strings including % then web application is exposing the path of Python in error.Application exposing path of Python in error when you enter the 3 or more strings including % .. if you only enter the 2 strings it will show you the 404 not found page ### POC : `https://gratipay.com/%ff/` [3 strings] **Request is undecodable.(/app/.heroku/python/lib/python2.7/encodings/utf_8.py:16)** `https://gratipay.com/%f/` [ 2 strings] - **404 Not Found**
Actions
View on HackerOne
Report Stats
  • Report ID: 138659
  • State: Closed
  • Substate: informative
  • Upvotes: 1
Share this report