5.2.6. Sink¶
5.2.6.1. 命令执行¶
bdb.os
cgi.os.system
cgi.sys
commands
ctypes.CDLL
eval
exec
execfile
os.exec
os.fork
os.popen
os.spawn
os.system
platform.os
platform.popen
platform.sys
popen2
pty.os
pty.spawn
subprocess
timeit.sys
timeit.timeit
…
5.2.6.2. 文件读取¶
open
os.open
urllib.request.urlopen(‘file:///’)
codecs.open
fileinput
- 仅Python2
types.FileType
5.2.6.3. 危险第三方库¶
Template
subprocess32
5.2.6.4. 反序列化¶
marshal
PyYAML
pickle
cPickle
shelve
PIL