Files
codeql/javascript/ql/src/Security/CWE-078/examples/command-injection.js
2023-07-05 12:02:11 +01:00

10 lines
240 B
JavaScript

var cp = require("child_process"),
http = require('http'),
url = require('url');
var server = http.createServer(function(req, res) {
let file = url.parse(req.url, true).query.path;
cp.execSync(`wc -l ${file}`); // BAD
});