|
1 | 1 | WARNING: Unused class Sink (/home/am/CodeQL-home/codeql-repo-amammad/javascript/ql/src/experimental/Security/CWE-094-dataURL/CodeInjection.ql:23,16-20)
|
2 | 2 | nodes
|
3 |
| -| test.js:18:11:18:44 | payload | |
4 |
| -| test.js:18:21:18:44 | req.que ... rameter | |
5 |
| -| test.js:18:21:18:44 | req.que ... rameter | |
6 |
| -| test.js:20:18:20:24 | payload | |
7 |
| -| test.js:20:18:20:24 | payload | |
| 3 | +| test.js:5:11:5:44 | payload | |
| 4 | +| test.js:5:21:5:44 | req.que ... rameter | |
| 5 | +| test.js:5:21:5:44 | req.que ... rameter | |
| 6 | +| test.js:6:9:6:43 | payloadURL | |
| 7 | +| test.js:6:22:6:43 | new URL ... + sth) | |
| 8 | +| test.js:6:30:6:36 | payload | |
| 9 | +| test.js:6:30:6:42 | payload + sth | |
| 10 | +| test.js:7:16:7:25 | payloadURL | |
| 11 | +| test.js:7:16:7:25 | payloadURL | |
| 12 | +| test.js:9:5:9:39 | payloadURL | |
| 13 | +| test.js:9:18:9:39 | new URL ... + sth) | |
| 14 | +| test.js:9:26:9:32 | payload | |
| 15 | +| test.js:9:26:9:38 | payload + sth | |
| 16 | +| test.js:10:16:10:25 | payloadURL | |
| 17 | +| test.js:10:16:10:25 | payloadURL | |
| 18 | +| test.js:17:11:17:44 | payload | |
| 19 | +| test.js:17:21:17:44 | req.que ... rameter | |
| 20 | +| test.js:17:21:17:44 | req.que ... rameter | |
| 21 | +| test.js:18:18:18:24 | payload | |
| 22 | +| test.js:18:18:18:24 | payload | |
| 23 | +| test.js:19:18:19:24 | payload | |
| 24 | +| test.js:19:18:19:30 | payload + sth | |
| 25 | +| test.js:19:18:19:30 | payload + sth | |
8 | 26 | edges
|
9 |
| -| test.js:18:11:18:44 | payload | test.js:20:18:20:24 | payload | |
10 |
| -| test.js:18:11:18:44 | payload | test.js:20:18:20:24 | payload | |
11 |
| -| test.js:18:21:18:44 | req.que ... rameter | test.js:18:11:18:44 | payload | |
12 |
| -| test.js:18:21:18:44 | req.que ... rameter | test.js:18:11:18:44 | payload | |
| 27 | +| test.js:5:11:5:44 | payload | test.js:6:30:6:36 | payload | |
| 28 | +| test.js:5:11:5:44 | payload | test.js:9:26:9:32 | payload | |
| 29 | +| test.js:5:21:5:44 | req.que ... rameter | test.js:5:11:5:44 | payload | |
| 30 | +| test.js:5:21:5:44 | req.que ... rameter | test.js:5:11:5:44 | payload | |
| 31 | +| test.js:6:9:6:43 | payloadURL | test.js:7:16:7:25 | payloadURL | |
| 32 | +| test.js:6:9:6:43 | payloadURL | test.js:7:16:7:25 | payloadURL | |
| 33 | +| test.js:6:22:6:43 | new URL ... + sth) | test.js:6:9:6:43 | payloadURL | |
| 34 | +| test.js:6:30:6:36 | payload | test.js:6:30:6:42 | payload + sth | |
| 35 | +| test.js:6:30:6:42 | payload + sth | test.js:6:22:6:43 | new URL ... + sth) | |
| 36 | +| test.js:9:5:9:39 | payloadURL | test.js:10:16:10:25 | payloadURL | |
| 37 | +| test.js:9:5:9:39 | payloadURL | test.js:10:16:10:25 | payloadURL | |
| 38 | +| test.js:9:18:9:39 | new URL ... + sth) | test.js:9:5:9:39 | payloadURL | |
| 39 | +| test.js:9:26:9:32 | payload | test.js:9:26:9:38 | payload + sth | |
| 40 | +| test.js:9:26:9:38 | payload + sth | test.js:9:18:9:39 | new URL ... + sth) | |
| 41 | +| test.js:17:11:17:44 | payload | test.js:18:18:18:24 | payload | |
| 42 | +| test.js:17:11:17:44 | payload | test.js:18:18:18:24 | payload | |
| 43 | +| test.js:17:11:17:44 | payload | test.js:19:18:19:24 | payload | |
| 44 | +| test.js:17:21:17:44 | req.que ... rameter | test.js:17:11:17:44 | payload | |
| 45 | +| test.js:17:21:17:44 | req.que ... rameter | test.js:17:11:17:44 | payload | |
| 46 | +| test.js:19:18:19:24 | payload | test.js:19:18:19:30 | payload + sth | |
| 47 | +| test.js:19:18:19:24 | payload | test.js:19:18:19:30 | payload + sth | |
13 | 48 | #select
|
14 |
| -| test.js:20:18:20:24 | payload | test.js:18:21:18:44 | req.que ... rameter | test.js:20:18:20:24 | payload | payload depends on a $@. | test.js:18:21:18:44 | req.que ... rameter | user-provided value | |
| 49 | +| test.js:7:16:7:25 | payloadURL | test.js:5:21:5:44 | req.que ... rameter | test.js:7:16:7:25 | payloadURL | payloadURL depends on a $@. | test.js:5:21:5:44 | req.que ... rameter | user-provided value | |
| 50 | +| test.js:10:16:10:25 | payloadURL | test.js:5:21:5:44 | req.que ... rameter | test.js:10:16:10:25 | payloadURL | payloadURL depends on a $@. | test.js:5:21:5:44 | req.que ... rameter | user-provided value | |
| 51 | +| test.js:18:18:18:24 | payload | test.js:17:21:17:44 | req.que ... rameter | test.js:18:18:18:24 | payload | payload depends on a $@. | test.js:17:21:17:44 | req.que ... rameter | user-provided value | |
| 52 | +| test.js:19:18:19:30 | payload + sth | test.js:17:21:17:44 | req.que ... rameter | test.js:19:18:19:30 | payload + sth | payload + sth depends on a $@. | test.js:17:21:17:44 | req.que ... rameter | user-provided value | |
0 commit comments