#6 Remote OS command execution

Chiuso
aperto 5 anni fa da sindre · 0 commenti
sindre 5 anni fa ha commentato

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre aggiunta alle pietre miliari Required fixes 5 anni fa
sindre added the
bug
label 5 anni fa
sindre added the
webpy
label 5 anni fa
sindre added the
injection
label 5 anni fa
sindre ha fatto riferimento a questa issue dal commit 5 anni fa
Effettua l'accesso per partecipare alla conversazione.
Loading…
Annulla
Salva
Non ci sono ancora contenuti.