|
33 | 33 | | forms.js:57:19:57:32 | e.target.value |
|
34 | 34 | | forms.js:57:19:57:32 | e.target.value |
|
35 | 35 | | forms.js:57:19:57:32 | e.target.value |
|
| 36 | +| forms.js:71:21:71:24 | data | |
| 37 | +| forms.js:71:21:71:24 | data | |
| 38 | +| forms.js:72:19:72:22 | data | |
| 39 | +| forms.js:72:19:72:27 | data.name | |
| 40 | +| forms.js:72:19:72:27 | data.name | |
| 41 | +| forms.js:92:17:92:36 | values | |
| 42 | +| forms.js:92:26:92:36 | getValues() | |
| 43 | +| forms.js:92:26:92:36 | getValues() | |
| 44 | +| forms.js:93:25:93:30 | values | |
| 45 | +| forms.js:93:25:93:35 | values.name | |
| 46 | +| forms.js:93:25:93:35 | values.name | |
36 | 47 | | xss-through-dom.js:2:16:2:34 | $("textarea").val() |
|
37 | 48 | | xss-through-dom.js:2:16:2:34 | $("textarea").val() |
|
38 | 49 | | xss-through-dom.js:2:16:2:34 | $("textarea").val() |
|
@@ -110,6 +121,15 @@ edges
|
110 | 121 | | forms.js:45:21:45:26 | values | forms.js:45:21:45:33 | values.stooge |
|
111 | 122 | | forms.js:45:21:45:26 | values | forms.js:45:21:45:33 | values.stooge |
|
112 | 123 | | forms.js:57:19:57:32 | e.target.value | forms.js:57:19:57:32 | e.target.value |
|
| 124 | +| forms.js:71:21:71:24 | data | forms.js:72:19:72:22 | data | |
| 125 | +| forms.js:71:21:71:24 | data | forms.js:72:19:72:22 | data | |
| 126 | +| forms.js:72:19:72:22 | data | forms.js:72:19:72:27 | data.name | |
| 127 | +| forms.js:72:19:72:22 | data | forms.js:72:19:72:27 | data.name | |
| 128 | +| forms.js:92:17:92:36 | values | forms.js:93:25:93:30 | values | |
| 129 | +| forms.js:92:26:92:36 | getValues() | forms.js:92:17:92:36 | values | |
| 130 | +| forms.js:92:26:92:36 | getValues() | forms.js:92:17:92:36 | values | |
| 131 | +| forms.js:93:25:93:30 | values | forms.js:93:25:93:35 | values.name | |
| 132 | +| forms.js:93:25:93:30 | values | forms.js:93:25:93:35 | values.name | |
113 | 133 | | xss-through-dom.js:2:16:2:34 | $("textarea").val() | xss-through-dom.js:2:16:2:34 | $("textarea").val() |
|
114 | 134 | | xss-through-dom.js:4:16:4:40 | $(".som ... .text() | xss-through-dom.js:4:16:4:40 | $(".som ... .text() |
|
115 | 135 | | xss-through-dom.js:8:16:8:53 | $(".som ... arget") | xss-through-dom.js:8:16:8:53 | $(".som ... arget") |
|
@@ -137,6 +157,8 @@ edges
|
137 | 157 | | forms.js:35:19:35:30 | values.email | forms.js:34:13:34:18 | values | forms.js:35:19:35:30 | values.email | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:34:13:34:18 | values | DOM text |
|
138 | 158 | | forms.js:45:21:45:33 | values.stooge | forms.js:44:21:44:26 | values | forms.js:45:21:45:33 | values.stooge | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:44:21:44:26 | values | DOM text |
|
139 | 159 | | forms.js:57:19:57:32 | e.target.value | forms.js:57:19:57:32 | e.target.value | forms.js:57:19:57:32 | e.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:57:19:57:32 | e.target.value | DOM text |
|
| 160 | +| forms.js:72:19:72:27 | data.name | forms.js:71:21:71:24 | data | forms.js:72:19:72:27 | data.name | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:71:21:71:24 | data | DOM text | |
| 161 | +| forms.js:93:25:93:35 | values.name | forms.js:92:26:92:36 | getValues() | forms.js:93:25:93:35 | values.name | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:92:26:92:36 | getValues() | DOM text | |
140 | 162 | | xss-through-dom.js:2:16:2:34 | $("textarea").val() | xss-through-dom.js:2:16:2:34 | $("textarea").val() | xss-through-dom.js:2:16:2:34 | $("textarea").val() | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:2:16:2:34 | $("textarea").val() | DOM text |
|
141 | 163 | | xss-through-dom.js:4:16:4:40 | $(".som ... .text() | xss-through-dom.js:4:16:4:40 | $(".som ... .text() | xss-through-dom.js:4:16:4:40 | $(".som ... .text() | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:4:16:4:40 | $(".som ... .text() | DOM text |
|
142 | 164 | | xss-through-dom.js:8:16:8:53 | $(".som ... arget") | xss-through-dom.js:8:16:8:53 | $(".som ... arget") | xss-through-dom.js:8:16:8:53 | $(".som ... arget") | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:8:16:8:53 | $(".som ... arget") | DOM text |
|
|
0 commit comments