lnln1111 / webgoat

Automatically exported from code.google.com/p/webgoat
0 stars 0 forks source link

Command Injection lesson is immediately completed on Ubuntu #34

Closed GoogleCodeExporter closed 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1. Run WebGoat in Ubuntu
2. Start the Command Injection lesson
3. Congratulations. You have successfully completed this lesson. (twice in
fact)

What is the expected output? What do you see instead?
  Expected output is a lesson to complete.  What you see instead is:

  * Congratulations. You have successfully completed this lesson.
  * Congratulations. You have successfully completed this lesson.
  You are currently viewing: BasicAuthentication.help

  Select the lesson plan to view:

  ExecResults for '/bin/sh'
  Output...

What version of the product are you using? On what operating system?
WebGoat-OWASP_Standard-5.3_RC1 on Ubuntu 9.10

Please provide any additional information below.
None.

Original issue reported on code.google.com by tspencer...@gmail.com on 26 Jan 2010 at 9:50

GoogleCodeExporter commented 9 years ago

Original comment by mayhe...@gmail.com on 26 Jan 2010 at 1:15

GoogleCodeExporter commented 9 years ago
BTW, as stated this was using 5.3_RC1, but 5.2 has the same behavior.

Original comment by tspencer...@gmail.com on 26 Jan 2010 at 11:39

GoogleCodeExporter commented 9 years ago
Fixed in 5.4

Original comment by mayhe...@gmail.com on 23 Apr 2012 at 10:47