@@ -11,17 +11,15 @@ extensions:
1111 data :
1212 - ["group:xorm", "Engine", True, "Alias", "", "", "Argument[0]", "sql-injection", "manual"]
1313 - ["group:xorm", "Engine", True, "And", "", "", "Argument[0]", "sql-injection", "manual"]
14- - ["group:xorm", " Engine", True, "Exec", "", "", "Argument[0]", "sql-injection", "manual"]
14+ # Engine.Exec has to be modeled in QL to select only the first syntactic argument
1515 - ["group:xorm", "Engine", True, "GroupBy", "", "", "Argument[0]", "sql-injection", "manual"]
1616 - ["group:xorm", "Engine", True, "Having", "", "", "Argument[0]", "sql-injection", "manual"]
1717 - ["group:xorm", "Engine", True, "In", "", "", "Argument[0]", "sql-injection", "manual"]
1818 - ["group:xorm", "Engine", True, "Join", "", "", "Argument[0..2]", "sql-injection", "manual"]
1919 - ["group:xorm", "Engine", True, "NotIn", "", "", "Argument[0]", "sql-injection", "manual"]
2020 - ["group:xorm", "Engine", True, "Or", "", "", "Argument[0]", "sql-injection", "manual"]
2121 - ["group:xorm", "Engine", True, "OrderBy", "", "", "Argument[0]", "sql-injection", "manual"]
22- - ["group:xorm", "Engine", True, "Query", "", "", "Argument[0]", "sql-injection", "manual"]
23- - ["group:xorm", "Engine", True, "QueryString", "", "", "Argument[0]", "sql-injection", "manual"]
24- - ["group:xorm", "Engine", True, "QueryInterface", "", "", "Argument[0]", "sql-injection", "manual"]
22+ # Engine.Query, Engine.QueryInterface and Engine.QueryString have to be modeled in QL to select only the first syntactic argument
2523 - ["group:xorm", "Engine", True, "Select", "", "", "Argument[0]", "sql-injection", "manual"]
2624 - ["group:xorm", "Engine", True, "SetExpr", "", "", "Argument[0]", "sql-injection", "manual"]
2725 - ["group:xorm", "Engine", True, "SQL", "", "", "Argument[0]", "sql-injection", "manual"]
@@ -32,17 +30,15 @@ extensions:
3230 - ["group:xorm", "Engine", True, "Where", "", "", "Argument[0]", "sql-injection", "manual"]
3331 - ["group:xorm", "Session", True, "Alias", "", "", "Argument[0]", "sql-injection", "manual"]
3432 - ["group:xorm", "Session", True, "And", "", "", "Argument[0]", "sql-injection", "manual"]
35- - ["group:xorm", " Session", True, "Exec", "", "", "Argument[0]", "sql-injection", "manual"]
33+ # Session.Exec has to be modeled in QL to select only the first syntactic argument
3634 - ["group:xorm", "Session", True, "GroupBy", "", "", "Argument[0]", "sql-injection", "manual"]
3735 - ["group:xorm", "Session", True, "Having", "", "", "Argument[0]", "sql-injection", "manual"]
3836 - ["group:xorm", "Session", True, "In", "", "", "Argument[0]", "sql-injection", "manual"]
3937 - ["group:xorm", "Session", True, "Join", "", "", "Argument[0..2]", "sql-injection", "manual"]
4038 - ["group:xorm", "Session", True, "NotIn", "", "", "Argument[0]", "sql-injection", "manual"]
4139 - ["group:xorm", "Session", True, "Or", "", "", "Argument[0]", "sql-injection", "manual"]
4240 - ["group:xorm", "Session", True, "OrderBy", "", "", "Argument[0]", "sql-injection", "manual"]
43- - ["group:xorm", "Session", True, "Query", "", "", "Argument[0]", "sql-injection", "manual"]
44- - ["group:xorm", "Session", True, "QueryString", "", "", "Argument[0]", "sql-injection", "manual"]
45- - ["group:xorm", "Session", True, "QueryInterface", "", "", "Argument[0]", "sql-injection", "manual"]
41+ # Session.Query, Session.QueryInterface and Session.QueryString have to be modeled in QL to select only the first syntactic argument
4642 - ["group:xorm", "Session", True, "Select", "", "", "Argument[0]", "sql-injection", "manual"]
4743 - ["group:xorm", "Session", True, "SetExpr", "", "", "Argument[0]", "sql-injection", "manual"]
4844 - ["group:xorm", "Session", True, "SQL", "", "", "Argument[0]", "sql-injection", "manual"]
0 commit comments