@@ -109,6 +109,8 @@ nodes
109
109
| other.js:23:28:23:30 | cmd |
110
110
| other.js:26:34:26:36 | cmd |
111
111
| other.js:26:34:26:36 | cmd |
112
+ | other.js:28:27:28:29 | cmd |
113
+ | other.js:28:27:28:29 | cmd |
112
114
| third-party-command-injection.js:5:20:5:26 | command |
113
115
| third-party-command-injection.js:5:20:5:26 | command |
114
116
| third-party-command-injection.js:6:21:6:27 | command |
@@ -213,6 +215,8 @@ edges
213
215
| other.js:5:9:5:49 | cmd | other.js:23:28:23:30 | cmd |
214
216
| other.js:5:9:5:49 | cmd | other.js:26:34:26:36 | cmd |
215
217
| other.js:5:9:5:49 | cmd | other.js:26:34:26:36 | cmd |
218
+ | other.js:5:9:5:49 | cmd | other.js:28:27:28:29 | cmd |
219
+ | other.js:5:9:5:49 | cmd | other.js:28:27:28:29 | cmd |
216
220
| other.js:5:15:5:38 | url.par ... , true) | other.js:5:15:5:44 | url.par ... ).query |
217
221
| other.js:5:15:5:44 | url.par ... ).query | other.js:5:15:5:49 | url.par ... ry.path |
218
222
| other.js:5:15:5:49 | url.par ... ry.path | other.js:5:9:5:49 | cmd |
@@ -261,4 +265,5 @@ edges
261
265
| other.js:22:21:22:23 | cmd | other.js:5:25:5:31 | req.url | other.js:22:21:22:23 | cmd | This command depends on $@. | other.js:5:25:5:31 | req.url | a user-provided value |
262
266
| other.js:23:28:23:30 | cmd | other.js:5:25:5:31 | req.url | other.js:23:28:23:30 | cmd | This command depends on $@. | other.js:5:25:5:31 | req.url | a user-provided value |
263
267
| other.js:26:34:26:36 | cmd | other.js:5:25:5:31 | req.url | other.js:26:34:26:36 | cmd | This command depends on $@. | other.js:5:25:5:31 | req.url | a user-provided value |
268
+ | other.js:28:27:28:29 | cmd | other.js:5:25:5:31 | req.url | other.js:28:27:28:29 | cmd | This command depends on $@. | other.js:5:25:5:31 | req.url | a user-provided value |
264
269
| third-party-command-injection.js:6:21:6:27 | command | third-party-command-injection.js:5:20:5:26 | command | third-party-command-injection.js:6:21:6:27 | command | This command depends on $@. | third-party-command-injection.js:5:20:5:26 | command | a server-provided value |
0 commit comments