Unsanitized User Input in File Path
Overview
Description
Remediation Guidelines
public class Cls extends HttpServlet { public void handleRequest(HttpServletRequest request, HttpServletResponse response) { String image = request.getParameter("user_profile_picture"); File file = new File("user/profile/" + FilenameUtils.getName(image)); } }
References
Configuration
PreviousUnsanitized User Input in File Path TraversalNextUnsanitized user input in format string detected
Last updated