Files
codeql/java/ql/src/Security/CWE/CWE-079/XSS.java
2018-08-30 10:48:05 +01:00

9 lines
368 B
Java

public class XSS extends HttpServlet {
protected void doGet(HttpServletRequest request, HttpServletResponse response)
throws ServletException, IOException {
// BAD: a request parameter is written directly to an error response page
response.sendError(HttpServletResponse.SC_NOT_FOUND,
"The page \"" + request.getParameter("page") + "\" was not found.");
}
}