Globbing in the tar
command results in parameter injection, resulting in code execution.
$ diff ./11.2.0/usr/local/bin/pan_log_export_ftp ./11.2.1/usr/local/bin/pan_log_export_ftp
5a6
> import tarfile
125c126
< shellCmd = "cd /opt/pancfg/mgmt/mdm/enterprise_appstore; tar -czf /opt/pancfg/mgmt/mdm/tmp/entappstore.tgz *"
---
> shellCmd = "cd /opt/pancfg/mgmt/mdm/enterprise_appstore"