Shell escape data:image/s3,"s3://crabby-images/e58e6/e58e67a641eff3e0198c045db6fa44b8d2a2243b" alt="cc4m_logo_inline"
ID | SECURITY-2 |
Title | Do not use the shell escape function. |
Priority | Mandatory |
Severity level | 3 |
Description | Do not use the shell escape function. If necessary, use the system function instead. |
Rationale | When using the !program_to_execute syntax to execute external programs, no dynamic input or program names can be used. |
Exception | Application development. |
Avoid:
!mycommand
Instead use:
system('mycommand')