#6 Remote OS command execution

Gesloten
5 jaren geleden werd geopend door sindre · 0 opmerkingen

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre added this to the Required fixes milestone 5 jaren geleden
sindre added the
bug
label 5 jaren geleden
sindre added the
webpy
label 5 jaren geleden
sindre added the
injection
label 5 jaren geleden
Log in om deel te nemen aan deze discussie.
Laden…
Annuleren
Opslaan
Er is nog geen inhoud.