|
57 | 57 | | express.js:155:18:155:23 | target |
|
58 | 58 | | express.js:160:18:160:23 | target |
|
59 | 59 | | express.js:160:18:160:23 | target |
|
| 60 | +| express.js:164:7:164:54 | myThing | |
| 61 | +| express.js:164:17:164:41 | JSON.st ... .query) | |
| 62 | +| express.js:164:17:164:54 | JSON.st ... (1, -1) | |
| 63 | +| express.js:164:32:164:40 | req.query | |
| 64 | +| express.js:164:32:164:40 | req.query | |
| 65 | +| express.js:165:16:165:22 | myThing | |
| 66 | +| express.js:165:16:165:22 | myThing | |
60 | 67 | | koa.js:6:6:6:27 | url |
|
61 | 68 | | koa.js:6:12:6:27 | ctx.query.target |
|
62 | 69 | | koa.js:6:12:6:27 | ctx.query.target |
|
@@ -153,6 +160,12 @@ edges
|
153 | 160 | | express.js:150:7:150:34 | target | express.js:160:18:160:23 | target |
|
154 | 161 | | express.js:150:16:150:34 | req.param("target") | express.js:150:7:150:34 | target |
|
155 | 162 | | express.js:150:16:150:34 | req.param("target") | express.js:150:7:150:34 | target |
|
| 163 | +| express.js:164:7:164:54 | myThing | express.js:165:16:165:22 | myThing | |
| 164 | +| express.js:164:7:164:54 | myThing | express.js:165:16:165:22 | myThing | |
| 165 | +| express.js:164:17:164:41 | JSON.st ... .query) | express.js:164:17:164:54 | JSON.st ... (1, -1) | |
| 166 | +| express.js:164:17:164:54 | JSON.st ... (1, -1) | express.js:164:7:164:54 | myThing | |
| 167 | +| express.js:164:32:164:40 | req.query | express.js:164:17:164:41 | JSON.st ... .query) | |
| 168 | +| express.js:164:32:164:40 | req.query | express.js:164:17:164:41 | JSON.st ... .query) | |
156 | 169 | | koa.js:6:6:6:27 | url | koa.js:7:15:7:17 | url |
|
157 | 170 | | koa.js:6:6:6:27 | url | koa.js:7:15:7:17 | url |
|
158 | 171 | | koa.js:6:6:6:27 | url | koa.js:8:18:8:20 | url |
|
@@ -214,6 +227,7 @@ edges
|
214 | 227 | | express.js:146:16:146:24 | query.foo | express.js:146:16:146:24 | query.foo | express.js:146:16:146:24 | query.foo | Untrusted URL redirection depends on a $@. | express.js:146:16:146:24 | query.foo | user-provided value |
|
215 | 228 | | express.js:155:18:155:23 | target | express.js:150:16:150:34 | req.param("target") | express.js:155:18:155:23 | target | Untrusted URL redirection depends on a $@. | express.js:150:16:150:34 | req.param("target") | user-provided value |
|
216 | 229 | | express.js:160:18:160:23 | target | express.js:150:16:150:34 | req.param("target") | express.js:160:18:160:23 | target | Untrusted URL redirection depends on a $@. | express.js:150:16:150:34 | req.param("target") | user-provided value |
|
| 230 | +| express.js:165:16:165:22 | myThing | express.js:164:32:164:40 | req.query | express.js:165:16:165:22 | myThing | Untrusted URL redirection depends on a $@. | express.js:164:32:164:40 | req.query | user-provided value | |
217 | 231 | | koa.js:7:15:7:17 | url | koa.js:6:12:6:27 | ctx.query.target | koa.js:7:15:7:17 | url | Untrusted URL redirection depends on a $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value |
|
218 | 232 | | koa.js:8:15:8:26 | `${url}${x}` | koa.js:6:12:6:27 | ctx.query.target | koa.js:8:15:8:26 | `${url}${x}` | Untrusted URL redirection depends on a $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value |
|
219 | 233 | | koa.js:14:16:14:18 | url | koa.js:6:12:6:27 | ctx.query.target | koa.js:14:16:14:18 | url | Untrusted URL redirection depends on a $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value |
|
|
0 commit comments