|
40 | 40 | | partial.js:28:14:28:18 | x + y | partial.js:31:47:31:53 | req.url | partial.js:28:14:28:18 | x + y | Cross-site scripting vulnerability due to a $@. | partial.js:31:47:31:53 | req.url | user-provided value |
|
41 | 41 | | partial.js:37:14:37:18 | x + y | partial.js:40:43:40:49 | req.url | partial.js:37:14:37:18 | x + y | Cross-site scripting vulnerability due to a $@. | partial.js:40:43:40:49 | req.url | user-provided value |
|
42 | 42 | | promises.js:6:25:6:25 | x | promises.js:5:44:5:57 | req.query.data | promises.js:6:25:6:25 | x | Cross-site scripting vulnerability due to a $@. | promises.js:5:44:5:57 | req.query.data | user-provided value |
|
| 43 | +| response-object.js:9:18:9:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:9:18:9:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 44 | +| response-object.js:10:18:10:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:10:18:10:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 45 | +| response-object.js:11:18:11:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:11:18:11:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 46 | +| response-object.js:14:18:14:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:14:18:14:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 47 | +| response-object.js:17:18:17:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:17:18:17:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 48 | +| response-object.js:23:18:23:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:23:18:23:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 49 | +| response-object.js:26:18:26:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:26:18:26:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 50 | +| response-object.js:34:18:34:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:34:18:34:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 51 | +| response-object.js:38:18:38:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:38:18:38:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
43 | 52 | | tst2.js:7:12:7:12 | p | tst2.js:6:9:6:9 | p | tst2.js:7:12:7:12 | p | Cross-site scripting vulnerability due to a $@. | tst2.js:6:9:6:9 | p | user-provided value |
|
44 | 53 | | tst2.js:8:12:8:12 | r | tst2.js:6:12:6:15 | q: r | tst2.js:8:12:8:12 | r | Cross-site scripting vulnerability due to a $@. | tst2.js:6:12:6:15 | q: r | user-provided value |
|
45 | 54 | | tst2.js:18:12:18:12 | p | tst2.js:14:9:14:9 | p | tst2.js:18:12:18:12 | p | Cross-site scripting vulnerability due to a $@. | tst2.js:14:9:14:9 | p | user-provided value |
|
@@ -149,6 +158,16 @@ edges
|
149 | 158 | | promises.js:5:36:5:42 | [post update] resolve [resolve-value] | promises.js:5:16:5:22 | resolve [Return] [resolve-value] | provenance | |
|
150 | 159 | | promises.js:5:44:5:57 | req.query.data | promises.js:5:36:5:42 | [post update] resolve [resolve-value] | provenance | |
|
151 | 160 | | promises.js:6:11:6:11 | x | promises.js:6:25:6:25 | x | provenance | |
|
| 161 | +| response-object.js:7:11:7:25 | data | response-object.js:9:18:9:21 | data | provenance | | |
| 162 | +| response-object.js:7:11:7:25 | data | response-object.js:10:18:10:21 | data | provenance | | |
| 163 | +| response-object.js:7:11:7:25 | data | response-object.js:11:18:11:21 | data | provenance | | |
| 164 | +| response-object.js:7:11:7:25 | data | response-object.js:14:18:14:21 | data | provenance | | |
| 165 | +| response-object.js:7:11:7:25 | data | response-object.js:17:18:17:21 | data | provenance | | |
| 166 | +| response-object.js:7:11:7:25 | data | response-object.js:23:18:23:21 | data | provenance | | |
| 167 | +| response-object.js:7:11:7:25 | data | response-object.js:26:18:26:21 | data | provenance | | |
| 168 | +| response-object.js:7:11:7:25 | data | response-object.js:34:18:34:21 | data | provenance | | |
| 169 | +| response-object.js:7:11:7:25 | data | response-object.js:38:18:38:21 | data | provenance | | |
| 170 | +| response-object.js:7:18:7:25 | req.body | response-object.js:7:11:7:25 | data | provenance | | |
152 | 171 | | tst2.js:6:7:6:30 | p | tst2.js:7:12:7:12 | p | provenance | |
|
153 | 172 | | tst2.js:6:7:6:30 | r | tst2.js:8:12:8:12 | r | provenance | |
|
154 | 173 | | tst2.js:6:9:6:9 | p | tst2.js:6:7:6:30 | p | provenance | |
|
@@ -332,6 +351,17 @@ nodes
|
332 | 351 | | promises.js:5:44:5:57 | req.query.data | semmle.label | req.query.data |
|
333 | 352 | | promises.js:6:11:6:11 | x | semmle.label | x |
|
334 | 353 | | promises.js:6:25:6:25 | x | semmle.label | x |
|
| 354 | +| response-object.js:7:11:7:25 | data | semmle.label | data | |
| 355 | +| response-object.js:7:18:7:25 | req.body | semmle.label | req.body | |
| 356 | +| response-object.js:9:18:9:21 | data | semmle.label | data | |
| 357 | +| response-object.js:10:18:10:21 | data | semmle.label | data | |
| 358 | +| response-object.js:11:18:11:21 | data | semmle.label | data | |
| 359 | +| response-object.js:14:18:14:21 | data | semmle.label | data | |
| 360 | +| response-object.js:17:18:17:21 | data | semmle.label | data | |
| 361 | +| response-object.js:23:18:23:21 | data | semmle.label | data | |
| 362 | +| response-object.js:26:18:26:21 | data | semmle.label | data | |
| 363 | +| response-object.js:34:18:34:21 | data | semmle.label | data | |
| 364 | +| response-object.js:38:18:38:21 | data | semmle.label | data | |
335 | 365 | | tst2.js:6:7:6:30 | p | semmle.label | p |
|
336 | 366 | | tst2.js:6:7:6:30 | r | semmle.label | r |
|
337 | 367 | | tst2.js:6:9:6:9 | p | semmle.label | p |
|
|
0 commit comments