diff --git a/docs/labs/README.md b/docs/labs/README.md index 3447a74b..c94d6946 100644 --- a/docs/labs/README.md +++ b/docs/labs/README.md @@ -102,7 +102,7 @@ work on. * Introduction to Securely Calling Programs - The Basics * Calling Other Programs: Injection and Filenames * [SQL Injection](https://github.com/ossf/secure-sw-dev-fundamentals/blob/main/secure_software_development_fundamentals.md#sql-injection) - DONE-1 (@Elijah Everett, 2024-08-13) [sql-injection](sql-injection.html) - * OS Command (Shell) injection - DONE-1 (Marta Rybczynska) [shell-injection](shell-injection.html) + * OS Command (Shell) injection - DONE-1 (Marta Rybczynska) [shell-injection](shell-injection.html) [argument-injection](argument-injection.html) * [Other Injection Attacks](https://github.com/ossf/secure-sw-dev-fundamentals/blob/main/secure_software_development_fundamentals.md#other-injection-attacks) - PLANNED-2 (Dhananjay Arunesh via Vincent Danen, 2026-07-26) * Filenames (Including Path Traversal and Link Following) - PLANNED-2 UNASSIGNED * Calling Other Programs: Other Issues diff --git a/docs/labs/shell-argument-injection.html b/docs/labs/argument-injection.html similarity index 57% rename from docs/labs/shell-argument-injection.html rename to docs/labs/argument-injection.html index 9d52eccf..aafa4e69 100644 --- a/docs/labs/shell-argument-injection.html +++ b/docs/labs/argument-injection.html @@ -14,60 +14,123 @@ execFile('git', ['blame', '--', filePath], { shell: false }, (error, stdout, stderr) => { -