This version contains mistakes, making it deprecated. Deprecated test cases should not be used for new work. However, They remain in the SARD as a reference to redo previous work.


CWE: 113 HTTP Response Splitting
BadSource: Environment Read a string from an environment variable
GoodSource: A hardcoded string
Sinks: addCookieServlet
GoodSink: URLEncode input
BadSink : querystring to addCookie()
Flow Variant: 52 Data flow: data passed as an argument from one method to another to another in three different classes in the same package


