#6 Remote OS command execution

已關閉
sindre5 年之前建立 · 0 條評論

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.

The first time a user uploads a file to a task there is a new foldercreated by using the taskid. Tampering with the task id can allow for command injection when executing OS command swith the popen function in the Python os package.
sindre 新增至Required fixes 里程碑 5 年之前
sindre added the
bug
label 5 年之前
sindre added the
webpy
label 5 年之前
sindre added the
injection
label 5 年之前
sindre 在代碼提交 5 年之前 中引用了該問題
sindre5 年之前 關閉
登入 才能加入這對話。
Loading…
取消
儲存
尚未有任何內容