public override void Bad(HttpRequest req, HttpResponse resp) { string data; data = ""; /* initialize data in case id is not in query string */ /* POTENTIAL FLAW: Parse id param out of the URL querystring (without using getParameter()) */ { if (req.QueryString["id"] != null) { data = req.QueryString["id"]; } } Container dataContainer = new Container(); dataContainer.containerOne = data; CWE314_Cleartext_Storage_in_the_Registry__QueryString_Web_67b.BadSink(dataContainer, req, resp); }