|
42 | 42 | | xss-through-dom.js:154:25:154:27 | msg | xss-through-dom.js:155:27:155:29 | msg | provenance | |
|
43 | 43 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | xss-through-dom.js:154:25:154:27 | msg | provenance | |
|
44 | 44 | nodes
|
45 |
| -| angular.ts:11:24:11:41 | event.target.value | semmle.label | event.target.value | |
46 |
| -| angular.ts:15:24:15:35 | target.value | semmle.label | target.value | |
| 45 | +| angular.ts:12:24:12:41 | event.target.value | semmle.label | event.target.value | |
| 46 | +| angular.ts:16:24:16:35 | target.value | semmle.label | target.value | |
47 | 47 | | forms.js:8:23:8:28 | values | semmle.label | values |
|
48 | 48 | | forms.js:9:31:9:36 | values | semmle.label | values |
|
49 | 49 | | forms.js:9:31:9:40 | values.foo | semmle.label | values.foo |
|
@@ -126,8 +126,8 @@ nodes
|
126 | 126 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | semmle.label | $("textarea").val() |
|
127 | 127 | subpaths
|
128 | 128 | #select
|
129 |
| -| angular.ts:11:24:11:41 | event.target.value | angular.ts:11:24:11:41 | event.target.value | angular.ts:11:24:11:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:11:24:11:41 | event.target.value | DOM text | |
130 |
| -| angular.ts:15:24:15:35 | target.value | angular.ts:15:24:15:35 | target.value | angular.ts:15:24:15:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:15:24:15:35 | target.value | DOM text | |
| 129 | +| angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:12:24:12:41 | event.target.value | DOM text | |
| 130 | +| angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:16:24:16:35 | target.value | DOM text | |
131 | 131 | | forms.js:9:31:9:40 | values.foo | forms.js:8:23:8:28 | values | forms.js:9:31:9:40 | values.foo | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:8:23:8:28 | values | DOM text |
|
132 | 132 | | forms.js:12:31:12:40 | values.bar | forms.js:11:24:11:29 | values | forms.js:12:31:12:40 | values.bar | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:11:24:11:29 | values | DOM text |
|
133 | 133 | | forms.js:25:23:25:34 | values.email | forms.js:24:15:24:20 | values | forms.js:25:23:25:34 | values.email | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:24:15:24:20 | values | DOM text |
|
|
0 commit comments