var http = require('http'); var fs = require('fs'); var express = require('express'); express().get('/', function(req, res) { fs.readdir("/myDir", function (error, files1) { res.send(files1); // NOT OK }); }); /** * The essence of a real world vulnerability. */ http.createServer(function (req, res) { function format(files2) { var files3 = []; files2.sort(sort).forEach(function (file) { files3.push('