Files
codeql/javascript/ql/test/query-tests/Security/CWE-078/tst_shell-command-injection-from-environment.js
2019-10-21 23:31:55 +02:00

7 lines
216 B
JavaScript

var cp = require('child_process'),
path = require('path');
(function() {
cp.execFileSync('rm', ['-rf', path.join(__dirname, "temp")]); // GOOD
cp.execSync('rm -rf ' + path.join(__dirname, "temp")); // BAD
});