|
61 | 61 | | dragAndDrop.ts:73:29:73:39 | droppedHtml | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | dragAndDrop.ts:73:29:73:39 | droppedHtml | Cross-site scripting vulnerability due to $@. | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | user-provided value |
|
62 | 62 | | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | Cross-site scripting vulnerability due to $@. | event-handler-receiver.js:2:49:2:61 | location.href | user-provided value |
|
63 | 63 | | express.js:6:15:6:33 | req.param("wobble") | express.js:6:15:6:33 | req.param("wobble") | express.js:6:15:6:33 | req.param("wobble") | Cross-site scripting vulnerability due to $@. | express.js:6:15:6:33 | req.param("wobble") | user-provided value |
|
| 64 | +| interceptors.js:9:56:9:72 | userGeneratedHtml | interceptors.js:7:6:7:13 | response | interceptors.js:9:56:9:72 | userGeneratedHtml | Cross-site scripting vulnerability due to $@. | interceptors.js:7:6:7:13 | response | user-provided value | |
64 | 65 | | jquery.js:7:5:7:34 | "<div i ... + "\\">" | jquery.js:2:17:2:40 | documen ... .search | jquery.js:7:5:7:34 | "<div i ... + "\\">" | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value |
|
65 | 66 | | jquery.js:8:18:8:34 | "XSS: " + tainted | jquery.js:2:17:2:40 | documen ... .search | jquery.js:8:18:8:34 | "XSS: " + tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value |
|
66 | 67 | | jquery.js:10:5:10:40 | "<b>" + ... "</b>" | jquery.js:10:13:10:20 | location | jquery.js:10:5:10:40 | "<b>" + ... "</b>" | Cross-site scripting vulnerability due to $@. | jquery.js:10:13:10:20 | location | user-provided value |
|
@@ -351,6 +352,9 @@ edges
|
351 | 352 | | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | dragAndDrop.ts:71:13:71:61 | droppedHtml | provenance | |
|
352 | 353 | | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | provenance | |
|
353 | 354 | | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | provenance | Config |
|
| 355 | +| interceptors.js:7:6:7:13 | response | interceptors.js:8:35:8:42 | response | provenance | | |
| 356 | +| interceptors.js:8:15:8:47 | userGeneratedHtml | interceptors.js:9:56:9:72 | userGeneratedHtml | provenance | | |
| 357 | +| interceptors.js:8:35:8:42 | response | interceptors.js:8:15:8:47 | userGeneratedHtml | provenance | | |
354 | 358 | | jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted | provenance | |
|
355 | 359 | | jquery.js:2:7:2:40 | tainted | jquery.js:5:13:5:19 | tainted | provenance | |
|
356 | 360 | | jquery.js:2:7:2:40 | tainted | jquery.js:6:11:6:17 | tainted | provenance | |
|
@@ -952,6 +956,10 @@ nodes
|
952 | 956 | | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | semmle.label | '<h2><a ... ></h2>' |
|
953 | 957 | | event-handler-receiver.js:2:49:2:61 | location.href | semmle.label | location.href |
|
954 | 958 | | express.js:6:15:6:33 | req.param("wobble") | semmle.label | req.param("wobble") |
|
| 959 | +| interceptors.js:7:6:7:13 | response | semmle.label | response | |
| 960 | +| interceptors.js:8:15:8:47 | userGeneratedHtml | semmle.label | userGeneratedHtml | |
| 961 | +| interceptors.js:8:35:8:42 | response | semmle.label | response | |
| 962 | +| interceptors.js:9:56:9:72 | userGeneratedHtml | semmle.label | userGeneratedHtml | |
955 | 963 | | jquery.js:2:7:2:40 | tainted | semmle.label | tainted |
|
956 | 964 | | jquery.js:2:17:2:40 | documen ... .search | semmle.label | documen ... .search |
|
957 | 965 | | jquery.js:4:5:4:11 | tainted | semmle.label | tainted |
|
|
0 commit comments