In which languages is it a security hole to use user-supplied regular expression?

后端 未结 8 1564
爱一瞬间的悲伤
爱一瞬间的悲伤 2020-12-17 17:00

Edit: tchrist has informed me that my original accusations about Perl\'s insecurity are unfounded. However, the question still stands.

I know that i

8条回答
  •  北荒
    北荒 (楼主)
    2020-12-17 17:27

    I suspect ruby would allow /#{system("rm -rf really_important_directory")}/ - is that the kind of thing you're worried about?

提交回复
热议问题