From 52f7073a9e92bd8f81ba4fd7018d7bfe30d79c93 Mon Sep 17 00:00:00 2001 From: Ana Scolari <127357173+apsscolari@users.noreply.github.com> Date: Mon, 10 Mar 2025 17:32:41 -0700 Subject: [PATCH 1/2] Update test.py --- test.py | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/test.py b/test.py index 360ad4a..2c5c7e0 100644 --- a/test.py +++ b/test.py @@ -13,4 +13,9 @@ # main if __name__ == '__main__': +# critical vuln example +user_input = input("Enter filename to read: ") +with open(user_input, 'r') as file: # Vulnerable to directory traversal + content = file.read() + print('hello Github world') From 7ebf1b674fb4d85e620c9912f12038dd16cc08da Mon Sep 17 00:00:00 2001 From: Ana Scolari <127357173+apsscolari@users.noreply.github.com> Date: Mon, 10 Mar 2025 17:33:55 -0700 Subject: [PATCH 2/2] Update comment in test.py --- test.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/test.py b/test.py index 2c5c7e0..5cd4254 100644 --- a/test.py +++ b/test.py @@ -13,7 +13,7 @@ # main if __name__ == '__main__': -# critical vuln example +# critical vuln example APS user_input = input("Enter filename to read: ") with open(user_input, 'r') as file: # Vulnerable to directory traversal content = file.read()