コード例 #1
0
 public override void Bad(HttpRequest req, HttpResponse resp)
 {
     data = ""; /* initialize data in case id is not in query string */
     /* POTENTIAL FLAW: Parse id param out of the URL querystring (without using getParameter()) */
     {
         if (req.QueryString["id"] != null)
         {
             data = req.QueryString["id"];
         }
     }
     CWE36_Absolute_Path_Traversal__QueryString_Web_68b.BadSink(req, resp);
 }
コード例 #2
0
 /* goodG2B() - use goodsource and badsink */
 private static void GoodG2B(HttpRequest req, HttpResponse resp)
 {
     /* FIX: Use a hardcoded string */
     data = "foo";
     CWE36_Absolute_Path_Traversal__QueryString_Web_68b.GoodG2BSink(req, resp);
 }