#6 Remote OS command execution

已关闭
sindre5 年前创建 · 0 条评论
sindre 评论于 5 年前

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre 5 年前 添加了里程碑 Required fixes
sindre 添加了标签
bug
5 年前
sindre 添加了标签
webpy
5 年前
sindre 添加了标签
injection
5 年前
sindre5 年前 在代码提交中引用了该工单
sindre5 年前 关闭
登陆 并参与到对话中。
正在加载...
取消
保存
这个人很懒,什么都没留下。