#6 Remote OS command execution

Fechado
aberto por sindre 5 anos atrás · 0 comentários

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre adicionou esta issue para o marco Required fixes 5 anos atrás
sindre adicionou a etiqueta
bug
5 anos atrás
sindre adicionou a etiqueta
webpy
5 anos atrás
sindre adicionou a etiqueta
injection
5 anos atrás
Acesse para participar desta conversação.
Carregando…
Cancelar
Salvar
Ainda não há conteúdo.