@@ -157,6 +157,8 @@ nodes
157
157
| xss-through-dom.js:140:19:140:21 | src |
158
158
| xss-through-dom.js:141:25:141:27 | src |
159
159
| xss-through-dom.js:141:25:141:27 | src |
160
+ | xss-through-dom.js:150:24:150:26 | src |
161
+ | xss-through-dom.js:150:24:150:26 | src |
160
162
edges
161
163
| forms.js:8:23:8:28 | values | forms.js:9:31:9:36 | values |
162
164
| forms.js:8:23:8:28 | values | forms.js:9:31:9:36 | values |
@@ -257,6 +259,8 @@ edges
257
259
| xss-through-dom.js:139:11:139:52 | src | xss-through-dom.js:140:19:140:21 | src |
258
260
| xss-through-dom.js:139:11:139:52 | src | xss-through-dom.js:141:25:141:27 | src |
259
261
| xss-through-dom.js:139:11:139:52 | src | xss-through-dom.js:141:25:141:27 | src |
262
+ | xss-through-dom.js:139:11:139:52 | src | xss-through-dom.js:150:24:150:26 | src |
263
+ | xss-through-dom.js:139:11:139:52 | src | xss-through-dom.js:150:24:150:26 | src |
260
264
| xss-through-dom.js:139:17:139:52 | documen ... k").src | xss-through-dom.js:139:11:139:52 | src |
261
265
| xss-through-dom.js:139:17:139:52 | documen ... k").src | xss-through-dom.js:139:11:139:52 | src |
262
266
#select
@@ -302,3 +306,4 @@ edges
302
306
| xss-through-dom.js:132:16:132:23 | linkText | xss-through-dom.js:130:42:130:62 | dSelect ... tring() | xss-through-dom.js:132:16:132:23 | linkText | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:130:42:130:62 | dSelect ... tring() | DOM text |
303
307
| xss-through-dom.js:140:19:140:21 | src | xss-through-dom.js:139:17:139:52 | documen ... k").src | xss-through-dom.js:140:19:140:21 | src | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:139:17:139:52 | documen ... k").src | DOM text |
304
308
| xss-through-dom.js:141:25:141:27 | src | xss-through-dom.js:139:17:139:52 | documen ... k").src | xss-through-dom.js:141:25:141:27 | src | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:139:17:139:52 | documen ... k").src | DOM text |
309
+ | xss-through-dom.js:150:24:150:26 | src | xss-through-dom.js:139:17:139:52 | documen ... k").src | xss-through-dom.js:150:24:150:26 | src | $@ is reinterpreted as HTML without escaping meta-characters. | xss-through-dom.js:139:17:139:52 | documen ... k").src | DOM text |
0 commit comments