|
1 | | -nodes |
2 | | -| XpathInjectionBad.js:6:7:6:38 | userName | |
3 | | -| XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | |
4 | | -| XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | |
5 | | -| XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | |
6 | | -| XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | |
7 | | -| XpathInjectionBad.js:9:66:9:73 | userName | |
8 | | -| tst2.js:1:13:1:34 | documen ... on.hash | |
9 | | -| tst2.js:1:13:1:34 | documen ... on.hash | |
10 | | -| tst2.js:1:13:1:47 | documen ... ring(1) | |
11 | | -| tst2.js:2:27:2:31 | query | |
12 | | -| tst2.js:2:27:2:31 | query | |
13 | | -| tst2.js:3:19:3:23 | query | |
14 | | -| tst2.js:3:19:3:23 | query | |
15 | | -| tst.js:6:7:6:37 | tainted | |
16 | | -| tst.js:6:17:6:37 | req.par ... rName") | |
17 | | -| tst.js:6:17:6:37 | req.par ... rName") | |
18 | | -| tst.js:7:15:7:21 | tainted | |
19 | | -| tst.js:7:15:7:21 | tainted | |
20 | | -| tst.js:8:16:8:22 | tainted | |
21 | | -| tst.js:8:16:8:22 | tainted | |
22 | | -| tst.js:9:17:9:23 | tainted | |
23 | | -| tst.js:9:17:9:23 | tainted | |
24 | | -| tst.js:11:8:11:14 | tainted | |
25 | | -| tst.js:11:8:11:14 | tainted | |
26 | 1 | edges |
27 | 2 | | XpathInjectionBad.js:6:7:6:38 | userName | XpathInjectionBad.js:9:66:9:73 | userName | |
28 | 3 | | XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | XpathInjectionBad.js:6:7:6:38 | userName | |
29 | | -| XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | XpathInjectionBad.js:6:7:6:38 | userName | |
30 | | -| XpathInjectionBad.js:9:66:9:73 | userName | XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | |
31 | 4 | | XpathInjectionBad.js:9:66:9:73 | userName | XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | |
32 | 5 | | tst2.js:1:13:1:34 | documen ... on.hash | tst2.js:1:13:1:47 | documen ... ring(1) | |
33 | | -| tst2.js:1:13:1:34 | documen ... on.hash | tst2.js:1:13:1:47 | documen ... ring(1) | |
34 | | -| tst2.js:1:13:1:47 | documen ... ring(1) | tst2.js:2:27:2:31 | query | |
35 | 6 | | tst2.js:1:13:1:47 | documen ... ring(1) | tst2.js:2:27:2:31 | query | |
36 | 7 | | tst2.js:1:13:1:47 | documen ... ring(1) | tst2.js:3:19:3:23 | query | |
37 | | -| tst2.js:1:13:1:47 | documen ... ring(1) | tst2.js:3:19:3:23 | query | |
38 | 8 | | tst.js:6:7:6:37 | tainted | tst.js:7:15:7:21 | tainted | |
39 | | -| tst.js:6:7:6:37 | tainted | tst.js:7:15:7:21 | tainted | |
40 | | -| tst.js:6:7:6:37 | tainted | tst.js:8:16:8:22 | tainted | |
41 | 9 | | tst.js:6:7:6:37 | tainted | tst.js:8:16:8:22 | tainted | |
42 | 10 | | tst.js:6:7:6:37 | tainted | tst.js:9:17:9:23 | tainted | |
43 | | -| tst.js:6:7:6:37 | tainted | tst.js:9:17:9:23 | tainted | |
44 | 11 | | tst.js:6:7:6:37 | tainted | tst.js:11:8:11:14 | tainted | |
45 | | -| tst.js:6:7:6:37 | tainted | tst.js:11:8:11:14 | tainted | |
46 | | -| tst.js:6:17:6:37 | req.par ... rName") | tst.js:6:7:6:37 | tainted | |
47 | 12 | | tst.js:6:17:6:37 | req.par ... rName") | tst.js:6:7:6:37 | tainted | |
| 13 | +nodes |
| 14 | +| XpathInjectionBad.js:6:7:6:38 | userName | semmle.label | userName | |
| 15 | +| XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | semmle.label | req.par ... rName") | |
| 16 | +| XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | semmle.label | "//user ... text()" | |
| 17 | +| XpathInjectionBad.js:9:66:9:73 | userName | semmle.label | userName | |
| 18 | +| tst2.js:1:13:1:34 | documen ... on.hash | semmle.label | documen ... on.hash | |
| 19 | +| tst2.js:1:13:1:47 | documen ... ring(1) | semmle.label | documen ... ring(1) | |
| 20 | +| tst2.js:2:27:2:31 | query | semmle.label | query | |
| 21 | +| tst2.js:3:19:3:23 | query | semmle.label | query | |
| 22 | +| tst.js:6:7:6:37 | tainted | semmle.label | tainted | |
| 23 | +| tst.js:6:17:6:37 | req.par ... rName") | semmle.label | req.par ... rName") | |
| 24 | +| tst.js:7:15:7:21 | tainted | semmle.label | tainted | |
| 25 | +| tst.js:8:16:8:22 | tainted | semmle.label | tainted | |
| 26 | +| tst.js:9:17:9:23 | tainted | semmle.label | tainted | |
| 27 | +| tst.js:11:8:11:14 | tainted | semmle.label | tainted | |
| 28 | +subpaths |
48 | 29 | #select |
49 | 30 | | XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | XpathInjectionBad.js:9:34:9:96 | "//user ... text()" | XPath expression depends on a $@. | XpathInjectionBad.js:6:18:6:38 | req.par ... rName") | user-provided value | |
50 | 31 | | tst2.js:2:27:2:31 | query | tst2.js:1:13:1:34 | documen ... on.hash | tst2.js:2:27:2:31 | query | XPath expression depends on a $@. | tst2.js:1:13:1:34 | documen ... on.hash | user-provided value | |
|
0 commit comments