Files
codeql/javascript/ql/test/query-tests/Security/CWE-400/RemovePropertyInjection/tstNonExpr.js
2021-03-02 13:56:39 +00:00

11 lines
281 B
JavaScript

var http = require('http');
var url = require('url');
var server = http.createServer(function(req, res) {
var userVal = req.url;
var newProp = "$" + userVal;
x[newProp] = 23; // OK
res.setHeader(userVal, 'text/html'); // NOT OK
res.write("foo");
res.end("bar");
})