National Institute of Standards and Technology
Package illustrating a test case

Test case 156445

Description

This test takes in data from an argument, that is intended
to contain parameters for an 'ls' command. The test does not perform
checks for special characters, however, and it is possible to include
other, unexpected commands as part of the ls parameter set.
Metadata
- Base program: Apache Lenya
- Source Taint: FILE_CONTENTS
- Data Type: SIMPLE
- Data Flow: ADDRESS_AS_CONSTANT
- Control Flow: BREAK_WITH_LABEL

Flaws

Test Suites

Have any comments on this test case? Please, send us an email.