|
1 | 1 | nodes |
| 2 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | |
| 3 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | |
| 4 | +| NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 5 | +| NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 6 | +| NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
| 7 | +| NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
| 8 | +| NoSQLCodeInjection.js:19:36:19:43 | req.body | |
| 9 | +| NoSQLCodeInjection.js:19:36:19:43 | req.body | |
| 10 | +| NoSQLCodeInjection.js:19:36:19:48 | req.body.name | |
2 | 11 | | angularjs.js:10:22:10:29 | location | |
3 | 12 | | angularjs.js:10:22:10:29 | location | |
4 | 13 | | angularjs.js:10:22:10:36 | location.search | |
@@ -108,6 +117,14 @@ nodes |
108 | 117 | | tst.js:26:26:26:53 | locatio ... ring(1) | |
109 | 118 | | tst.js:26:26:26:53 | locatio ... ring(1) | |
110 | 119 | edges |
| 120 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 121 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 122 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 123 | +| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | |
| 124 | +| NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | |
| 125 | +| NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | |
| 126 | +| NoSQLCodeInjection.js:19:36:19:48 | req.body.name | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
| 127 | +| NoSQLCodeInjection.js:19:36:19:48 | req.body.name | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
111 | 128 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
112 | 129 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
113 | 130 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
@@ -212,6 +229,8 @@ edges |
212 | 229 | | tst.js:26:26:26:40 | location.search | tst.js:26:26:26:53 | locatio ... ring(1) | |
213 | 230 | | tst.js:26:26:26:40 | location.search | tst.js:26:26:26:53 | locatio ... ring(1) | |
214 | 231 | #select |
| 232 | +| NoSQLCodeInjection.js:18:24:18:37 | req.body.query | NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | $@ flows to here and is interpreted as code. | NoSQLCodeInjection.js:18:24:18:31 | req.body | User-provided value | |
| 233 | +| NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | $@ flows to here and is interpreted as code. | NoSQLCodeInjection.js:19:36:19:43 | req.body | User-provided value | |
215 | 234 | | angularjs.js:10:22:10:36 | location.search | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:10:22:10:29 | location | User-provided value | |
216 | 235 | | angularjs.js:13:23:13:37 | location.search | angularjs.js:13:23:13:30 | location | angularjs.js:13:23:13:37 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:13:23:13:30 | location | User-provided value | |
217 | 236 | | angularjs.js:16:28:16:42 | location.search | angularjs.js:16:28:16:35 | location | angularjs.js:16:28:16:42 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:16:28:16:35 | location | User-provided value | |
|
0 commit comments