@@ -143,10 +143,6 @@ nodes
143
143
| template-sinks.js:32:16:32:22 | tainted |
144
144
| template-sinks.js:33:17:33:23 | tainted |
145
145
| template-sinks.js:33:17:33:23 | tainted |
146
- | template-sinks.js:34:26:34:32 | tainted |
147
- | template-sinks.js:34:26:34:32 | tainted |
148
- | template-sinks.js:35:47:35:53 | tainted |
149
- | template-sinks.js:35:47:35:53 | tainted |
150
146
| tst.js:2:6:2:27 | documen ... on.href |
151
147
| tst.js:2:6:2:27 | documen ... on.href |
152
148
| tst.js:2:6:2:83 | documen ... t=")+8) |
@@ -185,9 +181,24 @@ nodes
185
181
| tst.js:35:28:35:33 | source |
186
182
| tst.js:37:33:37:38 | source |
187
183
| tst.js:37:33:37:38 | source |
188
- | webix.js:3:12:3:33 | documen ... on.hash |
189
- | webix.js:3:12:3:33 | documen ... on.hash |
190
- | webix.js:3:12:3:33 | documen ... on.hash |
184
+ | webix/webix.html:3:16:3:37 | documen ... on.hash |
185
+ | webix/webix.html:3:16:3:37 | documen ... on.hash |
186
+ | webix/webix.html:3:16:3:37 | documen ... on.hash |
187
+ | webix/webix.html:4:26:4:47 | documen ... on.hash |
188
+ | webix/webix.html:4:26:4:47 | documen ... on.hash |
189
+ | webix/webix.html:4:26:4:47 | documen ... on.hash |
190
+ | webix/webix.html:5:47:5:68 | documen ... on.hash |
191
+ | webix/webix.html:5:47:5:68 | documen ... on.hash |
192
+ | webix/webix.html:5:47:5:68 | documen ... on.hash |
193
+ | webix/webix.js:3:12:3:33 | documen ... on.hash |
194
+ | webix/webix.js:3:12:3:33 | documen ... on.hash |
195
+ | webix/webix.js:3:12:3:33 | documen ... on.hash |
196
+ | webix/webix.js:4:22:4:43 | documen ... on.hash |
197
+ | webix/webix.js:4:22:4:43 | documen ... on.hash |
198
+ | webix/webix.js:4:22:4:43 | documen ... on.hash |
199
+ | webix/webix.js:5:43:5:64 | documen ... on.hash |
200
+ | webix/webix.js:5:43:5:64 | documen ... on.hash |
201
+ | webix/webix.js:5:43:5:64 | documen ... on.hash |
191
202
edges
192
203
| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query |
193
204
| NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query |
@@ -281,10 +292,6 @@ edges
281
292
| template-sinks.js:18:9:18:31 | tainted | template-sinks.js:32:16:32:22 | tainted |
282
293
| template-sinks.js:18:9:18:31 | tainted | template-sinks.js:33:17:33:23 | tainted |
283
294
| template-sinks.js:18:9:18:31 | tainted | template-sinks.js:33:17:33:23 | tainted |
284
- | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:34:26:34:32 | tainted |
285
- | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:34:26:34:32 | tainted |
286
- | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:35:47:35:53 | tainted |
287
- | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:35:47:35:53 | tainted |
288
295
| template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:18:9:18:31 | tainted |
289
296
| template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:18:9:18:31 | tainted |
290
297
| tst.js:2:6:2:27 | documen ... on.href | tst.js:2:6:2:83 | documen ... t=")+8) |
@@ -317,7 +324,12 @@ edges
317
324
| tst.js:29:18:29:41 | documen ... .search | tst.js:29:18:29:82 | documen ... , "$1") |
318
325
| tst.js:29:18:29:41 | documen ... .search | tst.js:29:18:29:82 | documen ... , "$1") |
319
326
| tst.js:29:18:29:82 | documen ... , "$1") | tst.js:29:9:29:82 | source |
320
- | webix.js:3:12:3:33 | documen ... on.hash | webix.js:3:12:3:33 | documen ... on.hash |
327
+ | webix/webix.html:3:16:3:37 | documen ... on.hash | webix/webix.html:3:16:3:37 | documen ... on.hash |
328
+ | webix/webix.html:4:26:4:47 | documen ... on.hash | webix/webix.html:4:26:4:47 | documen ... on.hash |
329
+ | webix/webix.html:5:47:5:68 | documen ... on.hash | webix/webix.html:5:47:5:68 | documen ... on.hash |
330
+ | webix/webix.js:3:12:3:33 | documen ... on.hash | webix/webix.js:3:12:3:33 | documen ... on.hash |
331
+ | webix/webix.js:4:22:4:43 | documen ... on.hash | webix/webix.js:4:22:4:43 | documen ... on.hash |
332
+ | webix/webix.js:5:43:5:64 | documen ... on.hash | webix/webix.js:5:43:5:64 | documen ... on.hash |
321
333
#select
322
334
| NoSQLCodeInjection.js:18:24:18:37 | req.body.query | NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | This code execution depends on a $@. | NoSQLCodeInjection.js:18:24:18:31 | req.body | user-provided value |
323
335
| NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | This code execution depends on a $@. | NoSQLCodeInjection.js:19:36:19:43 | req.body | user-provided value |
@@ -366,8 +378,6 @@ edges
366
378
| template-sinks.js:31:19:31:25 | tainted | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:31:19:31:25 | tainted | Template, which may contain code, depends on a $@. | template-sinks.js:18:19:18:31 | req.query.foo | user-provided value |
367
379
| template-sinks.js:32:16:32:22 | tainted | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:32:16:32:22 | tainted | Template, which may contain code, depends on a $@. | template-sinks.js:18:19:18:31 | req.query.foo | user-provided value |
368
380
| template-sinks.js:33:17:33:23 | tainted | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:33:17:33:23 | tainted | Template, which may contain code, depends on a $@. | template-sinks.js:18:19:18:31 | req.query.foo | user-provided value |
369
- | template-sinks.js:34:26:34:32 | tainted | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:34:26:34:32 | tainted | Template, which may contain code, depends on a $@. | template-sinks.js:18:19:18:31 | req.query.foo | user-provided value |
370
- | template-sinks.js:35:47:35:53 | tainted | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:35:47:35:53 | tainted | Template, which may contain code, depends on a $@. | template-sinks.js:18:19:18:31 | req.query.foo | user-provided value |
371
381
| tst.js:2:6:2:83 | documen ... t=")+8) | tst.js:2:6:2:27 | documen ... on.href | tst.js:2:6:2:83 | documen ... t=")+8) | This code execution depends on a $@. | tst.js:2:6:2:27 | documen ... on.href | user-provided value |
372
382
| tst.js:5:12:5:33 | documen ... on.hash | tst.js:5:12:5:33 | documen ... on.hash | tst.js:5:12:5:33 | documen ... on.hash | This code execution depends on a $@. | tst.js:5:12:5:33 | documen ... on.hash | user-provided value |
373
383
| tst.js:14:10:14:74 | documen ... , "$1") | tst.js:14:10:14:33 | documen ... .search | tst.js:14:10:14:74 | documen ... , "$1") | This code execution depends on a $@. | tst.js:14:10:14:33 | documen ... .search | user-provided value |
@@ -379,4 +389,9 @@ edges
379
389
| tst.js:33:14:33:19 | source | tst.js:29:18:29:41 | documen ... .search | tst.js:33:14:33:19 | source | This code execution depends on a $@. | tst.js:29:18:29:41 | documen ... .search | user-provided value |
380
390
| tst.js:35:28:35:33 | source | tst.js:29:18:29:41 | documen ... .search | tst.js:35:28:35:33 | source | This code execution depends on a $@. | tst.js:29:18:29:41 | documen ... .search | user-provided value |
381
391
| tst.js:37:33:37:38 | source | tst.js:29:18:29:41 | documen ... .search | tst.js:37:33:37:38 | source | This code execution depends on a $@. | tst.js:29:18:29:41 | documen ... .search | user-provided value |
382
- | webix.js:3:12:3:33 | documen ... on.hash | webix.js:3:12:3:33 | documen ... on.hash | webix.js:3:12:3:33 | documen ... on.hash | This code execution depends on a $@. | webix.js:3:12:3:33 | documen ... on.hash | user-provided value |
392
+ | webix/webix.html:3:16:3:37 | documen ... on.hash | webix/webix.html:3:16:3:37 | documen ... on.hash | webix/webix.html:3:16:3:37 | documen ... on.hash | This code execution depends on a $@. | webix/webix.html:3:16:3:37 | documen ... on.hash | user-provided value |
393
+ | webix/webix.html:4:26:4:47 | documen ... on.hash | webix/webix.html:4:26:4:47 | documen ... on.hash | webix/webix.html:4:26:4:47 | documen ... on.hash | Template, which may contain code, depends on a $@. | webix/webix.html:4:26:4:47 | documen ... on.hash | user-provided value |
394
+ | webix/webix.html:5:47:5:68 | documen ... on.hash | webix/webix.html:5:47:5:68 | documen ... on.hash | webix/webix.html:5:47:5:68 | documen ... on.hash | Template, which may contain code, depends on a $@. | webix/webix.html:5:47:5:68 | documen ... on.hash | user-provided value |
395
+ | webix/webix.js:3:12:3:33 | documen ... on.hash | webix/webix.js:3:12:3:33 | documen ... on.hash | webix/webix.js:3:12:3:33 | documen ... on.hash | This code execution depends on a $@. | webix/webix.js:3:12:3:33 | documen ... on.hash | user-provided value |
396
+ | webix/webix.js:4:22:4:43 | documen ... on.hash | webix/webix.js:4:22:4:43 | documen ... on.hash | webix/webix.js:4:22:4:43 | documen ... on.hash | Template, which may contain code, depends on a $@. | webix/webix.js:4:22:4:43 | documen ... on.hash | user-provided value |
397
+ | webix/webix.js:5:43:5:64 | documen ... on.hash | webix/webix.js:5:43:5:64 | documen ... on.hash | webix/webix.js:5:43:5:64 | documen ... on.hash | Template, which may contain code, depends on a $@. | webix/webix.js:5:43:5:64 | documen ... on.hash | user-provided value |
0 commit comments