#6 Remote OS command execution

Slēgta
sindre atvēra pirms 5 gadiem · 0 komentāri
sindre komentēja pirms 5 gadiem

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre pievienoja atskaites punktu Required fixes pirms 5 gadiem
sindre pievienoja etiķeti
bug
pirms 5 gadiem
sindre pievienoja etiķeti
webpy
pirms 5 gadiem
sindre pievienoja etiķeti
injection
pirms 5 gadiem
Pierakstieties, lai pievienotos šai sarunai.
Notiek ielāde…
Atcelt
Saglabāt
Vēl nav satura.