@@ -118,6 +118,11 @@ nodes
118
118
| dates.js:18:31:18:66 | `Time i ... aint)}` |
119
119
| dates.js:18:42:18:64 | datefor ... taint) |
120
120
| dates.js:18:59:18:63 | taint |
121
+ | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' |
122
+ | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' |
123
+ | event-handler-receiver.js:2:49:2:56 | location |
124
+ | event-handler-receiver.js:2:49:2:56 | location |
125
+ | event-handler-receiver.js:2:49:2:61 | location.href |
121
126
| express.js:7:15:7:33 | req.param("wobble") |
122
127
| express.js:7:15:7:33 | req.param("wobble") |
123
128
| express.js:7:15:7:33 | req.param("wobble") |
@@ -751,6 +756,10 @@ edges
751
756
| dates.js:18:42:18:64 | datefor ... taint) | dates.js:18:31:18:66 | `Time i ... aint)}` |
752
757
| dates.js:18:42:18:64 | datefor ... taint) | dates.js:18:31:18:66 | `Time i ... aint)}` |
753
758
| dates.js:18:59:18:63 | taint | dates.js:18:42:18:64 | datefor ... taint) |
759
+ | event-handler-receiver.js:2:49:2:56 | location | event-handler-receiver.js:2:49:2:61 | location.href |
760
+ | event-handler-receiver.js:2:49:2:56 | location | event-handler-receiver.js:2:49:2:61 | location.href |
761
+ | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' |
762
+ | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' |
754
763
| express.js:7:15:7:33 | req.param("wobble") | express.js:7:15:7:33 | req.param("wobble") |
755
764
| jquery.js:2:7:2:40 | tainted | jquery.js:7:20:7:26 | tainted |
756
765
| jquery.js:2:7:2:40 | tainted | jquery.js:8:28:8:34 | tainted |
@@ -1255,6 +1264,7 @@ edges
1255
1264
| dates.js:13:31:13:72 | `Time i ... time)}` | dates.js:9:36:9:50 | window.location | dates.js:13:31:13:72 | `Time i ... time)}` | Cross-site scripting vulnerability due to $@. | dates.js:9:36:9:50 | window.location | user-provided value |
1256
1265
| dates.js:16:31:16:69 | `Time i ... aint)}` | dates.js:9:36:9:50 | window.location | dates.js:16:31:16:69 | `Time i ... aint)}` | Cross-site scripting vulnerability due to $@. | dates.js:9:36:9:50 | window.location | user-provided value |
1257
1266
| dates.js:18:31:18:66 | `Time i ... aint)}` | dates.js:9:36:9:50 | window.location | dates.js:18:31:18:66 | `Time i ... aint)}` | Cross-site scripting vulnerability due to $@. | dates.js:9:36:9:50 | window.location | user-provided value |
1267
+ | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | event-handler-receiver.js:2:49:2:56 | location | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | Cross-site scripting vulnerability due to $@. | event-handler-receiver.js:2:49:2:56 | location | user-provided value |
1258
1268
| express.js:7:15:7:33 | req.param("wobble") | express.js:7:15:7:33 | req.param("wobble") | express.js:7:15:7:33 | req.param("wobble") | Cross-site scripting vulnerability due to $@. | express.js:7:15:7:33 | req.param("wobble") | user-provided value |
1259
1269
| jquery.js:7:5:7:34 | "<div i ... + "\\">" | jquery.js:2:17:2:40 | documen ... .search | jquery.js:7:5:7:34 | "<div i ... + "\\">" | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value |
1260
1270
| jquery.js:8:18:8:34 | "XSS: " + tainted | jquery.js:2:17:2:33 | document.location | jquery.js:8:18:8:34 | "XSS: " + tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:33 | document.location | user-provided value |
0 commit comments