os.system() or os exec-family call
High
- Category
- Dangerous Code Execution
- Content
@app.route('/ping') def ping(): host = request.args.get('host', 'localhost') os.system("ping -c 1 " + host) # ❌ eval 注入 @app.route('/calc')- Confidence
- 99% confidence
- Finding
- os.system("ping -c 1 " + host)
