@@ -453,6 +453,23 @@ nodes
453
453
| tst.js:414:19:414:31 | target.taint8 |
454
454
| tst.js:415:18:415:30 | target.taint8 |
455
455
| tst.js:415:18:415:30 | target.taint8 |
456
+ | tst.js:422:7:422:46 | payload |
457
+ | tst.js:422:17:422:31 | window.location |
458
+ | tst.js:422:17:422:31 | window.location |
459
+ | tst.js:422:17:422:46 | window. ... bstr(1) |
460
+ | tst.js:423:18:423:24 | payload |
461
+ | tst.js:423:18:423:24 | payload |
462
+ | tst.js:425:7:425:55 | match |
463
+ | tst.js:425:15:425:29 | window.location |
464
+ | tst.js:425:15:425:29 | window.location |
465
+ | tst.js:425:15:425:55 | window. ... (\\w+)/) |
466
+ | tst.js:427:20:427:24 | match |
467
+ | tst.js:427:20:427:27 | match[1] |
468
+ | tst.js:427:20:427:27 | match[1] |
469
+ | tst.js:430:18:430:32 | window.location |
470
+ | tst.js:430:18:430:32 | window.location |
471
+ | tst.js:430:18:430:51 | window. ... '#')[1] |
472
+ | tst.js:430:18:430:51 | window. ... '#')[1] |
456
473
| typeahead.js:20:13:20:45 | target |
457
474
| typeahead.js:20:22:20:38 | document.location |
458
475
| typeahead.js:20:22:20:38 | document.location |
@@ -882,6 +899,21 @@ edges
882
899
| tst.js:414:19:414:31 | target.taint8 | tst.js:414:19:414:31 | target.taint8 |
883
900
| tst.js:414:19:414:31 | target.taint8 | tst.js:415:18:415:30 | target.taint8 |
884
901
| tst.js:414:19:414:31 | target.taint8 | tst.js:415:18:415:30 | target.taint8 |
902
+ | tst.js:422:7:422:46 | payload | tst.js:423:18:423:24 | payload |
903
+ | tst.js:422:7:422:46 | payload | tst.js:423:18:423:24 | payload |
904
+ | tst.js:422:17:422:31 | window.location | tst.js:422:17:422:46 | window. ... bstr(1) |
905
+ | tst.js:422:17:422:31 | window.location | tst.js:422:17:422:46 | window. ... bstr(1) |
906
+ | tst.js:422:17:422:46 | window. ... bstr(1) | tst.js:422:7:422:46 | payload |
907
+ | tst.js:425:7:425:55 | match | tst.js:427:20:427:24 | match |
908
+ | tst.js:425:15:425:29 | window.location | tst.js:425:15:425:55 | window. ... (\\w+)/) |
909
+ | tst.js:425:15:425:29 | window.location | tst.js:425:15:425:55 | window. ... (\\w+)/) |
910
+ | tst.js:425:15:425:55 | window. ... (\\w+)/) | tst.js:425:7:425:55 | match |
911
+ | tst.js:427:20:427:24 | match | tst.js:427:20:427:27 | match[1] |
912
+ | tst.js:427:20:427:24 | match | tst.js:427:20:427:27 | match[1] |
913
+ | tst.js:430:18:430:32 | window.location | tst.js:430:18:430:51 | window. ... '#')[1] |
914
+ | tst.js:430:18:430:32 | window.location | tst.js:430:18:430:51 | window. ... '#')[1] |
915
+ | tst.js:430:18:430:32 | window.location | tst.js:430:18:430:51 | window. ... '#')[1] |
916
+ | tst.js:430:18:430:32 | window.location | tst.js:430:18:430:51 | window. ... '#')[1] |
885
917
| typeahead.js:20:13:20:45 | target | typeahead.js:21:12:21:17 | target |
886
918
| typeahead.js:20:22:20:38 | document.location | typeahead.js:20:22:20:45 | documen ... .search |
887
919
| typeahead.js:20:22:20:38 | document.location | typeahead.js:20:22:20:45 | documen ... .search |
@@ -1009,6 +1041,9 @@ edges
1009
1041
| tst.js:403:18:403:30 | target.taint5 | tst.js:387:16:387:32 | document.location | tst.js:403:18:403:30 | target.taint5 | Cross-site scripting vulnerability due to $@. | tst.js:387:16:387:32 | document.location | user-provided value |
1010
1042
| tst.js:412:18:412:30 | target.taint7 | tst.js:387:16:387:32 | document.location | tst.js:412:18:412:30 | target.taint7 | Cross-site scripting vulnerability due to $@. | tst.js:387:16:387:32 | document.location | user-provided value |
1011
1043
| tst.js:415:18:415:30 | target.taint8 | tst.js:387:16:387:32 | document.location | tst.js:415:18:415:30 | target.taint8 | Cross-site scripting vulnerability due to $@. | tst.js:387:16:387:32 | document.location | user-provided value |
1044
+ | tst.js:423:18:423:24 | payload | tst.js:422:17:422:31 | window.location | tst.js:423:18:423:24 | payload | Cross-site scripting vulnerability due to $@. | tst.js:422:17:422:31 | window.location | user-provided value |
1045
+ | tst.js:427:20:427:27 | match[1] | tst.js:425:15:425:29 | window.location | tst.js:427:20:427:27 | match[1] | Cross-site scripting vulnerability due to $@. | tst.js:425:15:425:29 | window.location | user-provided value |
1046
+ | tst.js:430:18:430:51 | window. ... '#')[1] | tst.js:430:18:430:32 | window.location | tst.js:430:18:430:51 | window. ... '#')[1] | Cross-site scripting vulnerability due to $@. | tst.js:430:18:430:32 | window.location | user-provided value |
1012
1047
| typeahead.js:25:18:25:20 | val | typeahead.js:20:22:20:38 | document.location | typeahead.js:25:18:25:20 | val | Cross-site scripting vulnerability due to $@. | typeahead.js:20:22:20:38 | document.location | user-provided value |
1013
1048
| v-html.vue:2:8:2:23 | v-html=tainted | v-html.vue:6:42:6:58 | document.location | v-html.vue:2:8:2:23 | v-html=tainted | Cross-site scripting vulnerability due to $@. | v-html.vue:6:42:6:58 | document.location | user-provided value |
1014
1049
| winjs.js:3:43:3:49 | tainted | winjs.js:2:17:2:33 | document.location | winjs.js:3:43:3:49 | tainted | Cross-site scripting vulnerability due to $@. | winjs.js:2:17:2:33 | document.location | user-provided value |
0 commit comments