Yes, this exploit can be used on any script or program that uses system(), whatever language you use.
Using bash as the default /bin/sh is the real bug here.
Using bash as the default /bin/sh is the real bug here.
Unless that script or program sanitizes the environment before calling system(). In practice that might not presently be any scripts or programs, but it principle it's a tiny bit weaker than you say.