Tainted flow: 'download_url' from requests.post (line 128, network input) → requests.get (network output)
Medium
- Category
- Data Flow
- Content
download_url = token_data.get('data') # 2. 真实下载种子文件并写入临时文件 (走代理) dl_resp = requests.get( download_url, headers=COMMON_HEADERS, proxies=PROXIES,- Confidence
- 94% confidence
- Finding
- dl_resp = requests.get( download_url, headers=COMMON_HEADERS, proxies=PROXIES, timeout=15 )
