Files
codeql/javascript/ql/src/Security/CWE-078/examples/shell-command-injection-from-environment.js
2019-10-21 23:31:55 +02:00

7 lines
169 B
JavaScript

var cp = require("child_process"),
path = require("path");
function cleanupTemp() {
let cmd = "rm -rf " + path.join(__dirname, "temp");
cp.execSync(cmd); // BAD
}