Files
codeql/python/ql/test/query-tests/Security/CWE-094/code_injection.py
2018-11-19 15:15:54 +00:00

13 lines
322 B
Python

from django.conf.urls import url
import base64
def code_execution(request):
if request.method == 'POST':
first_name = request.POST.get('first_name', '')
exec(base64.decodestring(first_name))
urlpatterns = [
# Route to code_execution
url(r'^code-ex$', code_execution, name='code-execution')
]