mirror of
https://github.com/github/codeql.git
synced 2025-12-17 09:13:20 +01:00
9 lines
331 B
JavaScript
9 lines
331 B
JavaScript
var express = require('express');
|
|
|
|
express().get('/user/', function(req, res) {
|
|
var evil = req.query.evil; // $ Source
|
|
res.send(console.log("<div>%s</div>", evil)); // OK - returns undefined
|
|
res.send(util.format("<div>%s</div>", evil)); // $ Alert
|
|
res.send(require("printf")("<div>%s</div>", evil)); // $ Alert
|
|
});
|