5 ms·
Can you please provide just one? No other comment does that. And to be clear, I'm talking about providing at least one legit use for passing user input directl
by ircmaxell 12y ago
Can you please provide just one? No other comment does that.
And to be clear, I'm talking about providing at least one legit use for passing user input directly to exec without any kind of filtering...
- scott_karana 12y agoThe sourcecode of a hypothetical Github commenting bot searching for this vulnerability will have the same search token, and will be flagged.
- andrewryno 12y agoA great example is: https://github.com/andresriancho/w3af-moth https://github.com/andresriancho/w3af-moth He deliberately wrote vulnerable code to test his auditing script. There are more repos like this.
- ircmaxell 12y agoThat's fair. But that's also the vast minority of these results that I can tell...
- TheCoelacanth 12y agoTest cases for a PHP vulnerability scanner[1] [1] https://news.ycombinator.com/item?id=7665232 https://news.ycombinator.com/item?id=7665232