15 lines
337 B
PHP
15 lines
337 B
PHP
<?php
|
|
|
|
$parts = explode("/", $_SERVER['PATH_INFO']);
|
|
$controllerName = $parts[0];
|
|
|
|
// ruleid: tainted-object-instantiation
|
|
$controller = new $controllerName($parts[1]);
|
|
|
|
// ok: tainted-object-instantiation
|
|
$controller = new MyController($controllerName);
|
|
|
|
// ok: tainted-object-instantiation
|
|
$a = "MyController";
|
|
$controller = new $a();
|