Files
codeql/python/ql/test/library-tests/dataflow/strange-essaflow/test.py
2024-04-23 09:40:44 +02:00

12 lines
227 B
Python

import os
from flask import Flask, request
app = Flask(__name__)
@app.route("/command1")
def command_injection1():
files = request.args.get('files', '')
# Don't let files be `; rm -rf /`
os.system("ls " + files)