|
1 | 1 | nodes
|
| 2 | +| actions.js:3:6:3:16 | process.env | |
| 3 | +| actions.js:3:6:3:16 | process.env | |
| 4 | +| actions.js:3:6:3:29 | process ... _DATA'] | |
| 5 | +| actions.js:3:6:3:29 | process ... _DATA'] | |
| 6 | +| actions.js:6:15:6:15 | e | |
| 7 | +| actions.js:7:10:7:10 | e | |
| 8 | +| actions.js:7:10:7:23 | e['TEST_DATA'] | |
| 9 | +| actions.js:7:10:7:23 | e['TEST_DATA'] | |
| 10 | +| actions.js:11:6:11:16 | process.env | |
| 11 | +| actions.js:11:6:11:16 | process.env | |
2 | 12 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
3 | 13 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
4 | 14 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
@@ -212,6 +222,15 @@ nodes
|
212 | 222 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType |
|
213 | 223 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType |
|
214 | 224 | edges
|
| 225 | +| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
| 226 | +| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
| 227 | +| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
| 228 | +| actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | |
| 229 | +| actions.js:6:15:6:15 | e | actions.js:7:10:7:10 | e | |
| 230 | +| actions.js:7:10:7:10 | e | actions.js:7:10:7:23 | e['TEST_DATA'] | |
| 231 | +| actions.js:7:10:7:10 | e | actions.js:7:10:7:23 | e['TEST_DATA'] | |
| 232 | +| actions.js:11:6:11:16 | process.env | actions.js:6:15:6:15 | e | |
| 233 | +| actions.js:11:6:11:16 | process.env | actions.js:6:15:6:15 | e | |
215 | 234 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv |
|
216 | 235 | | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:22:8:36 | process.argv[2] |
|
217 | 236 | | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:22:8:36 | process.argv[2] |
|
@@ -400,6 +419,8 @@ edges
|
400 | 419 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType | command-line-parameter-command-injection.js:146:10:146:38 | "cmd.sh ... zzaType |
|
401 | 420 | | command-line-parameter-command-injection.js:146:22:146:38 | program.pizzaType | command-line-parameter-command-injection.js:146:10:146:38 | "cmd.sh ... zzaType |
|
402 | 421 | #select
|
| 422 | +| actions.js:3:6:3:29 | process ... _DATA'] | actions.js:3:6:3:16 | process.env | actions.js:3:6:3:29 | process ... _DATA'] | This command depends on an unsanitized $@. | actions.js:3:6:3:16 | process.env | environment variable | |
| 423 | +| actions.js:7:10:7:23 | e['TEST_DATA'] | actions.js:11:6:11:16 | process.env | actions.js:7:10:7:23 | e['TEST_DATA'] | This command depends on an unsanitized $@. | actions.js:11:6:11:16 | process.env | environment variable | |
403 | 424 | | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:4:10:4:21 | process.argv | command-line argument |
|
404 | 425 | | command-line-parameter-command-injection.js:8:10:8:36 | "cmd.sh ... argv[2] | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line-parameter-command-injection.js:8:10:8:36 | "cmd.sh ... argv[2] | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:8:22:8:33 | process.argv | command-line argument |
|
405 | 426 | | command-line-parameter-command-injection.js:11:14:11:20 | args[0] | command-line-parameter-command-injection.js:10:13:10:24 | process.argv | command-line-parameter-command-injection.js:11:14:11:20 | args[0] | This command depends on an unsanitized $@. | command-line-parameter-command-injection.js:10:13:10:24 | process.argv | command-line argument |
|
|
0 commit comments