National Institute of Standards and Technology
Package illustrating a test case

Test case 156325

Description

This test takes in data from an argument, that is intended to contain parameters for an 'find' command. The test does not perform checks on the parameters, however, and it is possible to include other, unexpected commands as part of the find parameter set.

Metadata
-Base program: Apache Jena
- Source Taint: FILE_CONTENTS
- Data Type: simple
- Data Flow: address_as_function_return_value
- Control Flow: interclass_10

Flaws

Test Suites

Documentation

Have any comments on this test case? Please, send us an email.