@@ -431,6 +431,11 @@ nodes
431
431
| jquery.js:34:5:34:25 | '<b>' + ... '</b>' |
432
432
| jquery.js:34:5:34:25 | '<b>' + ... '</b>' |
433
433
| jquery.js:34:13:34:16 | hash |
434
+ | jquery.js:36:25:36:31 | tainted |
435
+ | jquery.js:36:25:36:31 | tainted |
436
+ | jquery.js:37:25:37:37 | () => tainted |
437
+ | jquery.js:37:25:37:37 | () => tainted |
438
+ | jquery.js:37:31:37:37 | tainted |
434
439
| json-stringify.jsx:5:9:5:36 | locale |
435
440
| json-stringify.jsx:5:9:5:36 | locale |
436
441
| json-stringify.jsx:5:18:5:36 | req.param("locale") |
@@ -1512,6 +1517,9 @@ edges
1512
1517
| express.js:7:15:7:33 | req.param("wobble") | express.js:7:15:7:33 | req.param("wobble") |
1513
1518
| jquery.js:2:7:2:40 | tainted | jquery.js:7:20:7:26 | tainted |
1514
1519
| jquery.js:2:7:2:40 | tainted | jquery.js:8:28:8:34 | tainted |
1520
+ | jquery.js:2:7:2:40 | tainted | jquery.js:36:25:36:31 | tainted |
1521
+ | jquery.js:2:7:2:40 | tainted | jquery.js:36:25:36:31 | tainted |
1522
+ | jquery.js:2:7:2:40 | tainted | jquery.js:37:31:37:37 | tainted |
1515
1523
| jquery.js:2:17:2:40 | documen ... .search | jquery.js:2:7:2:40 | tainted |
1516
1524
| jquery.js:2:17:2:40 | documen ... .search | jquery.js:2:7:2:40 | tainted |
1517
1525
| jquery.js:7:20:7:26 | tainted | jquery.js:7:5:7:34 | "<div i ... + "\\">" |
@@ -1565,6 +1573,8 @@ edges
1565
1573
| jquery.js:28:5:28:26 | window. ... .search | jquery.js:28:5:28:43 | window. ... ?', '') |
1566
1574
| jquery.js:34:13:34:16 | hash | jquery.js:34:5:34:25 | '<b>' + ... '</b>' |
1567
1575
| jquery.js:34:13:34:16 | hash | jquery.js:34:5:34:25 | '<b>' + ... '</b>' |
1576
+ | jquery.js:37:31:37:37 | tainted | jquery.js:37:25:37:37 | () => tainted |
1577
+ | jquery.js:37:31:37:37 | tainted | jquery.js:37:25:37:37 | () => tainted |
1568
1578
| json-stringify.jsx:5:9:5:36 | locale | json-stringify.jsx:11:51:11:56 | locale |
1569
1579
| json-stringify.jsx:5:9:5:36 | locale | json-stringify.jsx:19:56:19:61 | locale |
1570
1580
| json-stringify.jsx:5:9:5:36 | locale | json-stringify.jsx:31:55:31:60 | locale |
@@ -2355,6 +2365,8 @@ edges
2355
2365
| jquery.js:27:5:27:25 | hash.re ... #', '') | jquery.js:18:14:18:33 | window.location.hash | jquery.js:27:5:27:25 | hash.re ... #', '') | Cross-site scripting vulnerability due to $@. | jquery.js:18:14:18:33 | window.location.hash | user-provided value |
2356
2366
| jquery.js:28:5:28:43 | window. ... ?', '') | jquery.js:28:5:28:26 | window. ... .search | jquery.js:28:5:28:43 | window. ... ?', '') | Cross-site scripting vulnerability due to $@. | jquery.js:28:5:28:26 | window. ... .search | user-provided value |
2357
2367
| jquery.js:34:5:34:25 | '<b>' + ... '</b>' | jquery.js:18:14:18:33 | window.location.hash | jquery.js:34:5:34:25 | '<b>' + ... '</b>' | Cross-site scripting vulnerability due to $@. | jquery.js:18:14:18:33 | window.location.hash | user-provided value |
2368
+ | jquery.js:36:25:36:31 | tainted | jquery.js:2:17:2:40 | documen ... .search | jquery.js:36:25:36:31 | tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value |
2369
+ | jquery.js:37:25:37:37 | () => tainted | jquery.js:2:17:2:40 | documen ... .search | jquery.js:37:25:37:37 | () => tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value |
2358
2370
| json-stringify.jsx:31:40:31:61 | JSON.st ... locale) | json-stringify.jsx:5:18:5:36 | req.param("locale") | json-stringify.jsx:31:40:31:61 | JSON.st ... locale) | Cross-site scripting vulnerability due to $@. | json-stringify.jsx:5:18:5:36 | req.param("locale") | user-provided value |
2359
2371
| json-stringify.jsx:35:40:35:61 | JSON.st ... jsonLD) | json-stringify.jsx:5:18:5:36 | req.param("locale") | json-stringify.jsx:35:40:35:61 | JSON.st ... jsonLD) | Cross-site scripting vulnerability due to $@. | json-stringify.jsx:5:18:5:36 | req.param("locale") | user-provided value |
2360
2372
| jwt-server.js:11:19:11:29 | decoded.foo | jwt-server.js:7:17:7:35 | req.param("wobble") | jwt-server.js:11:19:11:29 | decoded.foo | Cross-site scripting vulnerability due to $@. | jwt-server.js:7:17:7:35 | req.param("wobble") | user-provided value |
0 commit comments