Author jcea
Date 2010-09-28.03:25:14
This issue is equivalent to MS Windows DLL hijacking (the MS situation is worse, because the DDL can be in network shares or, even , in remote webdav servers):

When I learned about this attack, my first thought was "what if sys.path.index('')>=0?". Arg!.
