Skip to content

ShellEscape aint always escaping shells #19906

Open
@Sim4n6

Description

@Sim4n6

Hey,

Does not this line mean if a user has defined a dummy function called shellescape() would be considered as a valid sanitizer ?

this.(DataFlow::CallNode).getMethodName() = "shellescape"

Thank you

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions