|
1 | 1 | nodes |
2 | | -| tst.js:243:9:243:31 | s().rep ... ]/g,'') | |
3 | | -| tst.js:243:9:243:31 | s().rep ... ]/g,'') | |
4 | | -| tst.js:243:9:243:31 | s().rep ... ]/g,'') | |
5 | | -| tst.js:244:9:244:33 | s().rep ... /g, '') | |
6 | | -| tst.js:244:9:244:33 | s().rep ... /g, '') | |
7 | | -| tst.js:244:9:244:33 | s().rep ... /g, '') | |
8 | | -| tst.js:249:9:249:33 | s().rep ... ]/g,'') | |
9 | | -| tst.js:249:9:249:33 | s().rep ... ]/g,'') | |
10 | | -| tst.js:249:9:249:33 | s().rep ... ]/g,'') | |
11 | | -| tst.js:250:9:250:33 | s().rep ... ]/g,'') | |
12 | | -| tst.js:250:9:250:33 | s().rep ... ]/g,'') | |
13 | | -| tst.js:250:9:250:33 | s().rep ... ]/g,'') | |
14 | | -| tst.js:253:21:253:45 | s().rep ... /g, '') | |
15 | | -| tst.js:253:21:253:45 | s().rep ... /g, '') | |
16 | | -| tst.js:253:21:253:45 | s().rep ... /g, '') | |
17 | | -| tst.js:254:32:254:56 | s().rep ... /g, '') | |
18 | | -| tst.js:254:32:254:56 | s().rep ... /g, '') | |
19 | | -| tst.js:254:32:254:56 | s().rep ... /g, '') | |
20 | | -| tst.js:270:61:270:85 | s().rep ... /g, '') | |
21 | | -| tst.js:270:61:270:85 | s().rep ... /g, '') | |
22 | | -| tst.js:270:61:270:85 | s().rep ... /g, '') | |
23 | | -| tst.js:274:6:274:94 | arr | |
24 | | -| tst.js:274:12:274:94 | s().val ... g , '') | |
25 | | -| tst.js:274:12:274:94 | s().val ... g , '') | |
26 | | -| tst.js:275:9:275:11 | arr | |
27 | | -| tst.js:275:9:275:21 | arr.join(" ") | |
28 | | -| tst.js:275:9:275:21 | arr.join(" ") | |
29 | | -| tst.js:300:10:300:33 | s().rep ... ]/g,'') | |
30 | | -| tst.js:300:10:300:33 | s().rep ... ]/g,'') | |
31 | | -| tst.js:300:10:300:33 | s().rep ... ]/g,'') | |
32 | | -| tst.js:301:10:301:32 | s().rep ... ]/g,'') | |
33 | | -| tst.js:301:10:301:32 | s().rep ... ]/g,'') | |
34 | | -| tst.js:301:10:301:32 | s().rep ... ]/g,'') | |
35 | | -| tst.js:302:10:302:34 | s().rep ... ]/g,'') | |
36 | | -| tst.js:302:10:302:34 | s().rep ... ]/g,'') | |
37 | | -| tst.js:302:10:302:34 | s().rep ... ]/g,'') | |
38 | | -| tst.js:303:10:303:34 | s().rep ... /g, '') | |
39 | | -| tst.js:303:10:303:34 | s().rep ... /g, '') | |
40 | | -| tst.js:303:10:303:34 | s().rep ... /g, '') | |
41 | | -| tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | |
42 | | -| tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | |
43 | | -| tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | |
| 2 | +| tst.js:243:9:243:31 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 3 | +| tst.js:244:9:244:33 | s().rep ... /g, '') | semmle.label | s().rep ... /g, '') | |
| 4 | +| tst.js:249:9:249:33 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 5 | +| tst.js:250:9:250:33 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 6 | +| tst.js:253:21:253:45 | s().rep ... /g, '') | semmle.label | s().rep ... /g, '') | |
| 7 | +| tst.js:254:32:254:56 | s().rep ... /g, '') | semmle.label | s().rep ... /g, '') | |
| 8 | +| tst.js:270:61:270:85 | s().rep ... /g, '') | semmle.label | s().rep ... /g, '') | |
| 9 | +| tst.js:274:6:274:94 | arr | semmle.label | arr | |
| 10 | +| tst.js:274:12:274:94 | s().val ... g , '') | semmle.label | s().val ... g , '') | |
| 11 | +| tst.js:275:9:275:11 | arr | semmle.label | arr | |
| 12 | +| tst.js:275:9:275:21 | arr.join(" ") | semmle.label | arr.join(" ") | |
| 13 | +| tst.js:300:10:300:33 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 14 | +| tst.js:301:10:301:32 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 15 | +| tst.js:302:10:302:34 | s().rep ... ]/g,'') | semmle.label | s().rep ... ]/g,'') | |
| 16 | +| tst.js:303:10:303:34 | s().rep ... /g, '') | semmle.label | s().rep ... /g, '') | |
| 17 | +| tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | semmle.label | s().rep ... ;";\\n\\t}) | |
44 | 18 | edges |
45 | | -| tst.js:243:9:243:31 | s().rep ... ]/g,'') | tst.js:243:9:243:31 | s().rep ... ]/g,'') | |
46 | | -| tst.js:244:9:244:33 | s().rep ... /g, '') | tst.js:244:9:244:33 | s().rep ... /g, '') | |
47 | | -| tst.js:249:9:249:33 | s().rep ... ]/g,'') | tst.js:249:9:249:33 | s().rep ... ]/g,'') | |
48 | | -| tst.js:250:9:250:33 | s().rep ... ]/g,'') | tst.js:250:9:250:33 | s().rep ... ]/g,'') | |
49 | | -| tst.js:253:21:253:45 | s().rep ... /g, '') | tst.js:253:21:253:45 | s().rep ... /g, '') | |
50 | | -| tst.js:254:32:254:56 | s().rep ... /g, '') | tst.js:254:32:254:56 | s().rep ... /g, '') | |
51 | | -| tst.js:270:61:270:85 | s().rep ... /g, '') | tst.js:270:61:270:85 | s().rep ... /g, '') | |
52 | 19 | | tst.js:274:6:274:94 | arr | tst.js:275:9:275:11 | arr | |
53 | 20 | | tst.js:274:12:274:94 | s().val ... g , '') | tst.js:274:6:274:94 | arr | |
54 | | -| tst.js:274:12:274:94 | s().val ... g , '') | tst.js:274:6:274:94 | arr | |
55 | | -| tst.js:275:9:275:11 | arr | tst.js:275:9:275:21 | arr.join(" ") | |
56 | 21 | | tst.js:275:9:275:11 | arr | tst.js:275:9:275:21 | arr.join(" ") | |
57 | | -| tst.js:300:10:300:33 | s().rep ... ]/g,'') | tst.js:300:10:300:33 | s().rep ... ]/g,'') | |
58 | | -| tst.js:301:10:301:32 | s().rep ... ]/g,'') | tst.js:301:10:301:32 | s().rep ... ]/g,'') | |
59 | | -| tst.js:302:10:302:34 | s().rep ... ]/g,'') | tst.js:302:10:302:34 | s().rep ... ]/g,'') | |
60 | | -| tst.js:303:10:303:34 | s().rep ... /g, '') | tst.js:303:10:303:34 | s().rep ... /g, '') | |
61 | | -| tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | tst.js:309:10:318:3 | s().rep ... ;";\\n\\t}) | |
| 22 | +subpaths |
62 | 23 | #select |
63 | 24 | | tst.js:243:9:243:31 | s().rep ... ]/g,'') | tst.js:243:9:243:31 | s().rep ... ]/g,'') | tst.js:243:9:243:31 | s().rep ... ]/g,'') | Cross-site scripting vulnerability as the output of $@ may contain double quotes when it reaches this attribute definition. | tst.js:243:9:243:31 | s().rep ... ]/g,'') | this final HTML sanitizer step | |
64 | 25 | | tst.js:244:9:244:33 | s().rep ... /g, '') | tst.js:244:9:244:33 | s().rep ... /g, '') | tst.js:244:9:244:33 | s().rep ... /g, '') | Cross-site scripting vulnerability as the output of $@ may contain double quotes when it reaches this attribute definition. | tst.js:244:9:244:33 | s().rep ... /g, '') | this final HTML sanitizer step | |
|
0 commit comments