rspec/rules/S4721/description.adoc
2020-12-21 15:38:52 +01:00

2 lines
224 B
Plaintext

Arbitrary OS command injection vulnerabilities are more likely when a shell is spawned rather than a new process, indeed shell meta-chars can be used (when parameters are user-controlled for instance) to inject OS commands.