|
23 | 23 | | tst.js:45:9:45:11 | obj |
|
24 | 24 | | tst.js:48:9:48:11 | obj |
|
25 | 25 | | tst.js:48:9:48:11 | obj |
|
| 26 | +| tst.js:78:5:78:37 | obj[req ... ', '')] | |
| 27 | +| tst.js:78:5:78:37 | obj[req ... ', '')] | |
| 28 | +| tst.js:78:9:78:19 | req.query.x | |
| 29 | +| tst.js:78:9:78:19 | req.query.x | |
| 30 | +| tst.js:78:9:78:36 | req.que ... _', '') | |
| 31 | +| tst.js:81:5:81:46 | obj[req ... g, '')] | |
| 32 | +| tst.js:81:5:81:46 | obj[req ... g, '')] | |
| 33 | +| tst.js:81:9:81:19 | req.query.x | |
| 34 | +| tst.js:81:9:81:19 | req.query.x | |
| 35 | +| tst.js:81:9:81:45 | req.que ... /g, '') | |
26 | 36 | edges
|
27 | 37 | | tst.js:5:9:5:38 | taint | tst.js:8:12:8:16 | taint |
|
28 | 38 | | tst.js:5:9:5:38 | taint | tst.js:9:12:9:16 | taint |
|
|
47 | 57 | | tst.js:33:23:33:25 | obj | tst.js:45:9:45:11 | obj |
|
48 | 58 | | tst.js:33:23:33:25 | obj | tst.js:48:9:48:11 | obj |
|
49 | 59 | | tst.js:33:23:33:25 | obj | tst.js:48:9:48:11 | obj |
|
| 60 | +| tst.js:78:9:78:19 | req.query.x | tst.js:78:9:78:36 | req.que ... _', '') | |
| 61 | +| tst.js:78:9:78:19 | req.query.x | tst.js:78:9:78:36 | req.que ... _', '') | |
| 62 | +| tst.js:78:9:78:36 | req.que ... _', '') | tst.js:78:5:78:37 | obj[req ... ', '')] | |
| 63 | +| tst.js:78:9:78:36 | req.que ... _', '') | tst.js:78:5:78:37 | obj[req ... ', '')] | |
| 64 | +| tst.js:81:9:81:19 | req.query.x | tst.js:81:9:81:45 | req.que ... /g, '') | |
| 65 | +| tst.js:81:9:81:19 | req.query.x | tst.js:81:9:81:45 | req.que ... /g, '') | |
| 66 | +| tst.js:81:9:81:45 | req.que ... /g, '') | tst.js:81:5:81:46 | obj[req ... g, '')] | |
| 67 | +| tst.js:81:9:81:45 | req.que ... /g, '') | tst.js:81:5:81:46 | obj[req ... g, '')] | |
50 | 68 | #select
|
51 | 69 | | tst.js:8:5:8:17 | object[taint] | tst.js:5:24:5:37 | req.query.data | tst.js:8:5:8:17 | object[taint] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | here |
|
52 | 70 | | tst.js:9:5:9:17 | object[taint] | tst.js:5:24:5:37 | req.query.data | tst.js:9:5:9:17 | object[taint] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | here |
|
|
55 | 73 | | tst.js:39:9:39:11 | obj | tst.js:5:24:5:37 | req.query.data | tst.js:39:9:39:11 | obj | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | here |
|
56 | 74 | | tst.js:45:9:45:11 | obj | tst.js:5:24:5:37 | req.query.data | tst.js:45:9:45:11 | obj | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | here |
|
57 | 75 | | tst.js:48:9:48:11 | obj | tst.js:5:24:5:37 | req.query.data | tst.js:48:9:48:11 | obj | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | here |
|
| 76 | +| tst.js:78:5:78:37 | obj[req ... ', '')] | tst.js:78:9:78:19 | req.query.x | tst.js:78:5:78:37 | obj[req ... ', '')] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:78:9:78:19 | req.query.x | here | |
| 77 | +| tst.js:81:5:81:46 | obj[req ... g, '')] | tst.js:81:9:81:19 | req.query.x | tst.js:81:5:81:46 | obj[req ... g, '')] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:81:9:81:19 | req.query.x | here | |
0 commit comments