|
64 | 64 | | angularjs.js:53:32:53:39 | location | |
65 | 65 | | angularjs.js:53:32:53:46 | location.search | |
66 | 66 | | angularjs.js:53:32:53:46 | location.search | |
| 67 | +| bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | |
| 68 | +| bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | |
| 69 | +| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | |
| 70 | +| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | |
| 71 | +| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | |
67 | 72 | | express.js:7:24:7:69 | "return ... + "];" | |
68 | 73 | | express.js:7:24:7:69 | "return ... + "];" | |
69 | 74 | | express.js:7:44:7:62 | req.param("wobble") | |
@@ -193,6 +198,10 @@ edges |
193 | 198 | | angularjs.js:53:32:53:39 | location | angularjs.js:53:32:53:46 | location.search | |
194 | 199 | | angularjs.js:53:32:53:39 | location | angularjs.js:53:32:53:46 | location.search | |
195 | 200 | | angularjs.js:53:32:53:39 | location | angularjs.js:53:32:53:46 | location.search | |
| 201 | +| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | |
| 202 | +| bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | |
| 203 | +| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | |
| 204 | +| bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:29:54:63 | JSON.st ... bble")) | |
196 | 205 | | express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" | |
197 | 206 | | express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" | |
198 | 207 | | express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" | |
@@ -261,6 +270,7 @@ edges |
261 | 270 | | angularjs.js:47:16:47:30 | location.search | angularjs.js:47:16:47:23 | location | angularjs.js:47:16:47:30 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:47:16:47:23 | location | User-provided value | |
262 | 271 | | angularjs.js:50:22:50:36 | location.search | angularjs.js:50:22:50:29 | location | angularjs.js:50:22:50:36 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:50:22:50:29 | location | User-provided value | |
263 | 272 | | angularjs.js:53:32:53:46 | location.search | angularjs.js:53:32:53:39 | location | angularjs.js:53:32:53:46 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:53:32:53:39 | location | User-provided value | |
| 273 | +| bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | bad-code-sanitization.js:54:14:54:67 | `(funct ... "))}))` | $@ flows to here and is interpreted as code. | bad-code-sanitization.js:54:44:54:62 | req.param("wobble") | User-provided value | |
264 | 274 | | express.js:7:24:7:69 | "return ... + "];" | express.js:7:44:7:62 | req.param("wobble") | express.js:7:24:7:69 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:7:44:7:62 | req.param("wobble") | User-provided value | |
265 | 275 | | express.js:9:34:9:79 | "return ... + "];" | express.js:9:54:9:72 | req.param("wobble") | express.js:9:34:9:79 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:9:54:9:72 | req.param("wobble") | User-provided value | |
266 | 276 | | express.js:12:8:12:53 | "return ... + "];" | express.js:12:28:12:46 | req.param("wobble") | express.js:12:8:12:53 | "return ... + "];" | $@ flows to here and is interpreted as code. | express.js:12:28:12:46 | req.param("wobble") | User-provided value | |
|
0 commit comments