Java: fix syntax error in path-injection example fix

This commit is contained in:
Chris Smowton
2022-12-02 10:04:53 +00:00
committed by GitHub
parent 7bf0e7ccc9
commit 6e98c67869

View File

@@ -16,9 +16,9 @@ public void sendUserFileFixed(Socket sock, String user) {
// ...
// GOOD: remove all dots and directory delimiters from the filename before using
String filename = filenameReader.readLine().replaceAll("\.", "").replaceAll("/", "");
String filename = filenameReader.readLine().replaceAll("\\.", "").replaceAll("/", "");
BufferedReader fileReader = new BufferedReader(
new FileReader("/home/" + user + "/" + filename));
// ...
}
}