...
- command processor via a call to
system()
or similar function. This is also addressed in ENV03-A. Sanitize the environment before invoking external programs. - external programs
- relational databases
- third-party COTS components (e.g., an enterprise resource planning subsystem)
...