Unsanitized User Input in OS Command
Overview
Description
Remediation Guidelines
String filePattern = "*.json"; if ("xml".equals(request.getParameter("format"))) { filePattern = "*.xml"; } Process process = Runtime.getRuntime().exec("ls /myDir/" + filePattern);
References
Configuration
Last updated