/* goodB2G() - use badsource and goodsink */ private static void GoodB2G() { /* get environment variable ADD */ /* POTENTIAL FLAW: Read data from an environment variable */ data = Environment.GetEnvironmentVariable("ADD"); CWE134_Externally_Controlled_Format_String__Environment_Format_68b.GoodB2GSink(); }
public override void Bad() { /* get environment variable ADD */ /* POTENTIAL FLAW: Read data from an environment variable */ data = Environment.GetEnvironmentVariable("ADD"); CWE134_Externally_Controlled_Format_String__Environment_Format_68b.BadSink(); }
/* goodG2B() - use goodsource and badsink */ private static void GoodG2B() { /* FIX: Use a hardcoded string */ data = "foo"; CWE134_Externally_Controlled_Format_String__Environment_Format_68b.GoodG2BSink(); }