Merge pull request #11540 from github/smowton/fix/path-injection-example-syntax-error

Java: fix syntax error in path-injection example fix
This commit is contained in:
Chris Smowton
2022-12-02 11:47:53 +00:00
committed by GitHub

View File

@@ -16,9 +16,9 @@ public void sendUserFileFixed(Socket sock, String user) {
// ...
// GOOD: remove all dots and directory delimiters from the filename before using
String filename = filenameReader.readLine().replaceAll("\.", "").replaceAll("/", "");
String filename = filenameReader.readLine().replaceAll("\\.", "").replaceAll("/", "");
BufferedReader fileReader = new BufferedReader(
new FileReader("/home/" + user + "/" + filename));
// ...
}
}