Files
codeql/python/ql/test/experimental/query-tests/Security-new-dataflow/CWE-094/code_injection.py
2020-10-07 21:12:31 +02:00

11 lines
234 B
Python

from flask import Flask, request
app = Flask(__name__)
@app.route("/code-execution")
def code_execution():
code = request.args.get("code")
exec(code)
eval(code)
cmd = compile(code, "<filename>", "exec")
exec(cmd)