Files
codeql/javascript/ql/src/Security/CWE-078/examples/shell-command-injection-from-environment_fixed.js
2019-10-21 23:31:55 +02:00

8 lines
194 B
JavaScript

var cp = require("child_process"),
path = require("path");
function cleanupTemp() {
let cmd = "rm",
args = ["-rf", path.join(__dirname, "temp")];
cp.execFileSync(cmd, args); // GOOD
}