=== on 16 Oct 2018, 11:27:12 Nicolas Harraudeau wrote:
*Implementation details*
The example shows two ways of setting ``++ProcessStartInfo.FileName++``, either directly or via the ``++StartInfo++`` attribute of a newly created ``++Process++``. From the analysis point of view this is the same as ``++Process.StartInfo++`` is a ``++ProcessStartInfo++``.
=== on 9 May 2019, 15:11:54 Nicolas Harraudeau wrote:
This rule is deprecated for C# because the taint analysis engine already covers command injection (RSPEC-2076).