...
ENV03-C. Sanitize the environment when invoking external programs | |
ENV03-CPP. Sanitize the environment when invoking external programs | |
SEI CERT Perl Coding Standard | IDS34-PL. Do not pass untrusted, unsanitized data to a command interpreter |
Injection [RST] | |
CWE-78, Improper Neutralization of Special Elements Used in an OS Command ("OS Command Injection") |
...
Chapter 5, "Handling Input," section "Command Injection" | |
[OWASP 2005] | A Guide to Building Secure Web Applications and Web Services |
[Permissions 2008] | Permissions in the Java™ SE 6 Development Kit (JDK) |
[Seacord 2015] | IDS07-J. Do not pass untrusted, unsanitized data to the Runtime.exec() method LiveLesson |
...