|
2 | 2 | | XXE.java:22:43:22:66 | getInputStream(...) : ServletInputStream | XXE.java:24:18:24:35 | servletInputStream |
|
3 | 3 | | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | XXE.java:32:17:32:18 | br : BufferedReader |
|
4 | 4 | | XXE.java:32:17:32:18 | br : BufferedReader | XXE.java:32:17:32:29 | readLine(...) : String |
|
5 |
| -| XXE.java:32:17:32:29 | readLine(...) : String | XXE.java:35:48:35:68 | toString(...) | |
| 5 | +| XXE.java:32:17:32:29 | readLine(...) : String | XXE.java:33:22:33:24 | str : String | |
| 6 | +| XXE.java:33:4:33:13 | listString [post update] : StringBuilder | XXE.java:35:48:35:57 | listString : StringBuilder | |
| 7 | +| XXE.java:33:22:33:24 | str : String | XXE.java:33:4:33:13 | listString [post update] : StringBuilder | |
| 8 | +| XXE.java:35:48:35:57 | listString : StringBuilder | XXE.java:35:48:35:68 | toString(...) | |
6 | 9 | | XXE.java:40:43:40:66 | getInputStream(...) : ServletInputStream | XXE.java:44:42:44:59 | servletInputStream : ServletInputStream |
|
7 | 10 | | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource | XXE.java:45:22:45:27 | source |
|
8 | 11 | | XXE.java:44:42:44:59 | servletInputStream : ServletInputStream | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource |
|
|
15 | 18 | | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | semmle.label | getReader(...) : BufferedReader |
|
16 | 19 | | XXE.java:32:17:32:18 | br : BufferedReader | semmle.label | br : BufferedReader |
|
17 | 20 | | XXE.java:32:17:32:29 | readLine(...) : String | semmle.label | readLine(...) : String |
|
| 21 | +| XXE.java:33:4:33:13 | listString [post update] : StringBuilder | semmle.label | listString [post update] : StringBuilder | |
| 22 | +| XXE.java:33:22:33:24 | str : String | semmle.label | str : String | |
| 23 | +| XXE.java:35:48:35:57 | listString : StringBuilder | semmle.label | listString : StringBuilder | |
18 | 24 | | XXE.java:35:48:35:68 | toString(...) | semmle.label | toString(...) |
|
19 | 25 | | XXE.java:40:43:40:66 | getInputStream(...) : ServletInputStream | semmle.label | getInputStream(...) : ServletInputStream |
|
20 | 26 | | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource | semmle.label | new StreamSource(...) : StreamSource |
|
|
25 | 31 | | XXE.java:51:42:51:59 | servletInputStream : ServletInputStream | semmle.label | servletInputStream : ServletInputStream |
|
26 | 32 | | XXE.java:52:3:52:12 | xmlDecoder | semmle.label | xmlDecoder |
|
27 | 33 | | XXE.java:57:49:57:72 | getInputStream(...) | semmle.label | getInputStream(...) |
|
| 34 | +subpaths |
28 | 35 | #select
|
29 | 36 | | XXE.java:24:18:24:35 | servletInputStream | XXE.java:22:43:22:66 | getInputStream(...) : ServletInputStream | XXE.java:24:18:24:35 | servletInputStream | Unsafe parsing of XML file from $@. | XXE.java:22:43:22:66 | getInputStream(...) | user input |
|
30 | 37 | | XXE.java:35:48:35:68 | toString(...) | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | XXE.java:35:48:35:68 | toString(...) | Unsafe parsing of XML file from $@. | XXE.java:29:23:29:41 | getReader(...) | user input |
|
|
0 commit comments