|
40 | 40 | | partial.js:28:14:28:18 | x + y | partial.js:31:47:31:53 | req.url | partial.js:28:14:28:18 | x + y | Cross-site scripting vulnerability due to a $@. | partial.js:31:47:31:53 | req.url | user-provided value |
|
41 | 41 | | partial.js:37:14:37:18 | x + y | partial.js:40:43:40:49 | req.url | partial.js:37:14:37:18 | x + y | Cross-site scripting vulnerability due to a $@. | partial.js:40:43:40:49 | req.url | user-provided value |
|
42 | 42 | | promises.js:6:25:6:25 | x | promises.js:5:44:5:57 | req.query.data | promises.js:6:25:6:25 | x | Cross-site scripting vulnerability due to a $@. | promises.js:5:44:5:57 | req.query.data | user-provided value |
|
| 43 | +| response-object.js:9:18:9:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:9:18:9:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 44 | +| response-object.js:10:18:10:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:10:18:10:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 45 | +| response-object.js:11:18:11:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:11:18:11:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 46 | +| response-object.js:13:18:13:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:13:18:13:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 47 | +| response-object.js:14:18:14:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:14:18:14:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 48 | +| response-object.js:16:18:16:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:16:18:16:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 49 | +| response-object.js:17:18:17:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:17:18:17:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 50 | +| response-object.js:20:18:20:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:20:18:20:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 51 | +| response-object.js:23:18:23:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:23:18:23:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 52 | +| response-object.js:26:18:26:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:26:18:26:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 53 | +| response-object.js:30:18:30:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:30:18:30:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 54 | +| response-object.js:34:18:34:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:34:18:34:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
| 55 | +| response-object.js:38:18:38:21 | data | response-object.js:7:18:7:25 | req.body | response-object.js:38:18:38:21 | data | Cross-site scripting vulnerability due to a $@. | response-object.js:7:18:7:25 | req.body | user-provided value | |
43 | 56 | | tst2.js:7:12:7:12 | p | tst2.js:6:9:6:9 | p | tst2.js:7:12:7:12 | p | Cross-site scripting vulnerability due to a $@. | tst2.js:6:9:6:9 | p | user-provided value |
|
44 | 57 | | tst2.js:8:12:8:12 | r | tst2.js:6:12:6:15 | q: r | tst2.js:8:12:8:12 | r | Cross-site scripting vulnerability due to a $@. | tst2.js:6:12:6:15 | q: r | user-provided value |
|
45 | 58 | | tst2.js:18:12:18:12 | p | tst2.js:14:9:14:9 | p | tst2.js:18:12:18:12 | p | Cross-site scripting vulnerability due to a $@. | tst2.js:14:9:14:9 | p | user-provided value |
|
@@ -149,6 +162,20 @@ edges
|
149 | 162 | | promises.js:5:36:5:42 | [post update] resolve [resolve-value] | promises.js:5:16:5:22 | resolve [Return] [resolve-value] | provenance | |
|
150 | 163 | | promises.js:5:44:5:57 | req.query.data | promises.js:5:36:5:42 | [post update] resolve [resolve-value] | provenance | |
|
151 | 164 | | promises.js:6:11:6:11 | x | promises.js:6:25:6:25 | x | provenance | |
|
| 165 | +| response-object.js:7:11:7:25 | data | response-object.js:9:18:9:21 | data | provenance | | |
| 166 | +| response-object.js:7:11:7:25 | data | response-object.js:10:18:10:21 | data | provenance | | |
| 167 | +| response-object.js:7:11:7:25 | data | response-object.js:11:18:11:21 | data | provenance | | |
| 168 | +| response-object.js:7:11:7:25 | data | response-object.js:13:18:13:21 | data | provenance | | |
| 169 | +| response-object.js:7:11:7:25 | data | response-object.js:14:18:14:21 | data | provenance | | |
| 170 | +| response-object.js:7:11:7:25 | data | response-object.js:16:18:16:21 | data | provenance | | |
| 171 | +| response-object.js:7:11:7:25 | data | response-object.js:17:18:17:21 | data | provenance | | |
| 172 | +| response-object.js:7:11:7:25 | data | response-object.js:20:18:20:21 | data | provenance | | |
| 173 | +| response-object.js:7:11:7:25 | data | response-object.js:23:18:23:21 | data | provenance | | |
| 174 | +| response-object.js:7:11:7:25 | data | response-object.js:26:18:26:21 | data | provenance | | |
| 175 | +| response-object.js:7:11:7:25 | data | response-object.js:30:18:30:21 | data | provenance | | |
| 176 | +| response-object.js:7:11:7:25 | data | response-object.js:34:18:34:21 | data | provenance | | |
| 177 | +| response-object.js:7:11:7:25 | data | response-object.js:38:18:38:21 | data | provenance | | |
| 178 | +| response-object.js:7:18:7:25 | req.body | response-object.js:7:11:7:25 | data | provenance | | |
152 | 179 | | tst2.js:6:7:6:30 | p | tst2.js:7:12:7:12 | p | provenance | |
|
153 | 180 | | tst2.js:6:7:6:30 | r | tst2.js:8:12:8:12 | r | provenance | |
|
154 | 181 | | tst2.js:6:9:6:9 | p | tst2.js:6:7:6:30 | p | provenance | |
|
@@ -332,6 +359,21 @@ nodes
|
332 | 359 | | promises.js:5:44:5:57 | req.query.data | semmle.label | req.query.data |
|
333 | 360 | | promises.js:6:11:6:11 | x | semmle.label | x |
|
334 | 361 | | promises.js:6:25:6:25 | x | semmle.label | x |
|
| 362 | +| response-object.js:7:11:7:25 | data | semmle.label | data | |
| 363 | +| response-object.js:7:18:7:25 | req.body | semmle.label | req.body | |
| 364 | +| response-object.js:9:18:9:21 | data | semmle.label | data | |
| 365 | +| response-object.js:10:18:10:21 | data | semmle.label | data | |
| 366 | +| response-object.js:11:18:11:21 | data | semmle.label | data | |
| 367 | +| response-object.js:13:18:13:21 | data | semmle.label | data | |
| 368 | +| response-object.js:14:18:14:21 | data | semmle.label | data | |
| 369 | +| response-object.js:16:18:16:21 | data | semmle.label | data | |
| 370 | +| response-object.js:17:18:17:21 | data | semmle.label | data | |
| 371 | +| response-object.js:20:18:20:21 | data | semmle.label | data | |
| 372 | +| response-object.js:23:18:23:21 | data | semmle.label | data | |
| 373 | +| response-object.js:26:18:26:21 | data | semmle.label | data | |
| 374 | +| response-object.js:30:18:30:21 | data | semmle.label | data | |
| 375 | +| response-object.js:34:18:34:21 | data | semmle.label | data | |
| 376 | +| response-object.js:38:18:38:21 | data | semmle.label | data | |
335 | 377 | | tst2.js:6:7:6:30 | p | semmle.label | p |
|
336 | 378 | | tst2.js:6:7:6:30 | r | semmle.label | r |
|
337 | 379 | | tst2.js:6:9:6:9 | p | semmle.label | p |
|
|
0 commit comments