Sobelow v0.2.4 Sobelow.CI

Command Injection

Command Injection vulnerabilities are a result of passing untrusted input to an operating system shell, and may result in complete system compromise.

Read more about Command Injection here: https://www.owasp.org/index.php/Command_Injection

Command Injection checks can be ignored with the following command:

$ mix sobelow -i CI

Summary

Functions

details()
get_details()
get_vulns(fun, filename, web_root)