...
Wiki Markup |
---|
This noncompliant code example uses the locale sensitive {{String.toUpperCase()}} method to convert an html tag to uppercase. This produces the string ""T?TLE"" in the Turkish locale wherein '?' is the Latin capital letter 'I' with a dot above the character \[[API 06|AA. Java References#API 06]\]. |
Code Block | ||
---|---|---|
| ||
"title""title".toUpperCase(); |
Compliant Solution
This compliant solution explicitly sets the locale to English to avoid the unexpected result.
Code Block | ||
---|---|---|
| ||
"title""title".toUpperCase(Locale.ENGLISH); |
...
Search for vulnerabilities resulting from the violation of this rule on the CERT website.
References
Wiki Markup |
---|
\[[API 06|AA. Java References#API 06]\] Class {{String}} |
...
IDS13-J. Properly encode or escape output 10. Input Validation and Data Sanitization (IDS) IDS15-J. Library methods should validate their parameters