Skip to content
/ sinks Public

Collection of sinks for Java vulnerability research 收集Java漏洞挖掘常见sink

Notifications You must be signed in to change notification settings

Hdys0vn/sinks

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

README

sinks:
  # 命令注入
  - { method: "<java.lang.Runtime: java.lang.Process exec(java.lang.String)>", index: 0 }
  - { method: "<java.lang.Runtime: java.lang.Process exec(java.lang.String[])>", index: 0 }
  - { method: "<java.lang.ProcessBuilder: java.lang.Process start()>", index: base }
  - { method: "<java.lang.ProcessImpl: java.lang.Process start()>", index: base }
  - { method: "<java.lang.UNIXProcess: java.lang.Process start()>", index: base }

method为函数签名,index表示关键参数的位置,0表示如果第一个参数用户可控则存在风险,base表示如果基变量用户可控则存在风险。

About

Collection of sinks for Java vulnerability research 收集Java漏洞挖掘常见sink

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published