The issue is described at https://buildsecurityin.us-cert.gov/...1/826-BSI.html
Would this code be vulnerable?
Would this code be vulnerable?
Code:
FUNCTION PBMAIN () AS LONG LOCAL shop AS SHFILEOPSTRUCT LOCAL shopQTHfrom,shopQTHto AS STRING LOCAL I AS LONG shopQTHfrom = "C:\temp\*.txt" + $NUL + $NUL shopQTHto = "C:\temp2" + $NUL + $NUL shop.pFrom = STRPTR(shopQTHfrom) shop.pTo = STRPTR(shopQTHto) shop.hwnd = 0 shop.wFunc = %FO_MOVE I = SHFILEOPERATION(shop) STDOUT "Result code = " + HEX$(I) WAITKEY$ END FUNCTION
Comment