|
1 | 1 | edges
|
2 |
| -| angular.ts:20:24:20:33 | form.value | angular.ts:20:24:20:37 | form.value.foo | provenance | | |
| 2 | +| angular.ts:23:24:23:33 | form.value | angular.ts:23:24:23:37 | form.value.foo | provenance | | |
3 | 3 | | forms.js:8:23:8:28 | values | forms.js:9:31:9:36 | values | provenance | |
|
4 | 4 | | forms.js:9:31:9:36 | values | forms.js:9:31:9:40 | values.foo | provenance | |
|
5 | 5 | | forms.js:11:24:11:29 | values | forms.js:12:31:12:36 | values | provenance | |
|
@@ -43,10 +43,10 @@ edges
|
43 | 43 | | xss-through-dom.js:154:25:154:27 | msg | xss-through-dom.js:155:27:155:29 | msg | provenance | |
|
44 | 44 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | xss-through-dom.js:154:25:154:27 | msg | provenance | |
|
45 | 45 | nodes
|
46 |
| -| angular.ts:12:24:12:41 | event.target.value | semmle.label | event.target.value | |
47 |
| -| angular.ts:16:24:16:35 | target.value | semmle.label | target.value | |
48 |
| -| angular.ts:20:24:20:33 | form.value | semmle.label | form.value | |
49 |
| -| angular.ts:20:24:20:37 | form.value.foo | semmle.label | form.value.foo | |
| 46 | +| angular.ts:15:24:15:41 | event.target.value | semmle.label | event.target.value | |
| 47 | +| angular.ts:19:24:19:35 | target.value | semmle.label | target.value | |
| 48 | +| angular.ts:23:24:23:33 | form.value | semmle.label | form.value | |
| 49 | +| angular.ts:23:24:23:37 | form.value.foo | semmle.label | form.value.foo | |
50 | 50 | | forms.js:8:23:8:28 | values | semmle.label | values |
|
51 | 51 | | forms.js:9:31:9:36 | values | semmle.label | values |
|
52 | 52 | | forms.js:9:31:9:40 | values.foo | semmle.label | values.foo |
|
@@ -129,9 +129,9 @@ nodes
|
129 | 129 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | semmle.label | $("textarea").val() |
|
130 | 130 | subpaths
|
131 | 131 | #select
|
132 |
| -| angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:12:24:12:41 | event.target.value | DOM text | |
133 |
| -| angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:16:24:16:35 | target.value | DOM text | |
134 |
| -| angular.ts:20:24:20:37 | form.value.foo | angular.ts:20:24:20:33 | form.value | angular.ts:20:24:20:37 | form.value.foo | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:20:24:20:33 | form.value | DOM text | |
| 132 | +| angular.ts:15:24:15:41 | event.target.value | angular.ts:15:24:15:41 | event.target.value | angular.ts:15:24:15:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:15:24:15:41 | event.target.value | DOM text | |
| 133 | +| angular.ts:19:24:19:35 | target.value | angular.ts:19:24:19:35 | target.value | angular.ts:19:24:19:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:19:24:19:35 | target.value | DOM text | |
| 134 | +| angular.ts:23:24:23:37 | form.value.foo | angular.ts:23:24:23:33 | form.value | angular.ts:23:24:23:37 | form.value.foo | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:23:24:23:33 | form.value | DOM text | |
135 | 135 | | forms.js:9:31:9:40 | values.foo | forms.js:8:23:8:28 | values | forms.js:9:31:9:40 | values.foo | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:8:23:8:28 | values | DOM text |
|
136 | 136 | | forms.js:12:31:12:40 | values.bar | forms.js:11:24:11:29 | values | forms.js:12:31:12:40 | values.bar | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:11:24:11:29 | values | DOM text |
|
137 | 137 | | forms.js:25:23:25:34 | values.email | forms.js:24:15:24:20 | values | forms.js:25:23:25:34 | values.email | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:24:15:24:20 | values | DOM text |
|
|
0 commit comments