Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: This is a rule, not a rec.

...

If the command string passed to system(), popen(), or other function that invokes a command processor is not fully sanitized, the risk of exploitation is high. In the worst case scenario, an attacker can execute arbitrary shellcode on the compromised machine with the privileges of the vulnerable process.

RecommendationRule

Severity

Likelihood

Remediation Cost

Priority

Level

ENV33-C

High

Probable

Medium

P12

L1

...