ngsankha / codejudge

host coding competitions anywhere, anytime
http://sankhs.com/codejudge
MIT License
90 stars 53 forks source link

The filename box can be exploited to execute shell commands #6

Closed ngsankha closed 12 years ago

ngsankha commented 12 years ago

The direct input of the Filename box is taken into compile.sh script file. By specially writing the filenames it is possible execute arbitrary shell commands on the server. This is a serious security flaw and should be fixed immediately.

The possible solutions are: