|
88 | 88 | | lib.js:92:3:92:12 | maybeProto |
|
89 | 89 | | lib.js:95:3:95:12 | maybeProto |
|
90 | 90 | | lib.js:95:3:95:12 | maybeProto |
|
| 91 | +| lib.js:104:7:104:24 | one | |
| 92 | +| lib.js:104:13:104:24 | arguments[1] | |
| 93 | +| lib.js:104:13:104:24 | arguments[1] | |
| 94 | +| lib.js:108:3:108:10 | obj[one] | |
| 95 | +| lib.js:108:3:108:10 | obj[one] | |
| 96 | +| lib.js:108:7:108:9 | one | |
91 | 97 | | tst.js:5:9:5:38 | taint |
|
92 | 98 | | tst.js:5:17:5:38 | String( ... y.data) |
|
93 | 99 | | tst.js:5:24:5:37 | req.query.data |
|
@@ -219,6 +225,11 @@ edges
|
219 | 225 | | lib.js:91:7:91:28 | maybeProto | lib.js:95:3:95:12 | maybeProto |
|
220 | 226 | | lib.js:91:20:91:28 | obj[path] | lib.js:91:7:91:28 | maybeProto |
|
221 | 227 | | lib.js:91:24:91:27 | path | lib.js:91:20:91:28 | obj[path] |
|
| 228 | +| lib.js:104:7:104:24 | one | lib.js:108:7:108:9 | one | |
| 229 | +| lib.js:104:13:104:24 | arguments[1] | lib.js:104:7:104:24 | one | |
| 230 | +| lib.js:104:13:104:24 | arguments[1] | lib.js:104:7:104:24 | one | |
| 231 | +| lib.js:108:7:108:9 | one | lib.js:108:3:108:10 | obj[one] | |
| 232 | +| lib.js:108:7:108:9 | one | lib.js:108:3:108:10 | obj[one] | |
222 | 233 | | tst.js:5:9:5:38 | taint | tst.js:8:12:8:16 | taint |
|
223 | 234 | | tst.js:5:9:5:38 | taint | tst.js:9:12:9:16 | taint |
|
224 | 235 | | tst.js:5:9:5:38 | taint | tst.js:12:25:12:29 | taint |
|
@@ -272,6 +283,7 @@ edges
|
272 | 283 | | lib.js:42:3:42:14 | obj[path[0]] | lib.js:40:14:40:20 | args[1] | lib.js:42:3:42:14 | obj[path[0]] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | lib.js:40:14:40:20 | args[1] | library input |
|
273 | 284 | | lib.js:70:13:70:24 | obj[path[0]] | lib.js:59:18:59:18 | s | lib.js:70:13:70:24 | obj[path[0]] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | lib.js:59:18:59:18 | s | library input |
|
274 | 285 | | lib.js:87:10:87:14 | proto | lib.js:83:14:83:25 | arguments[1] | lib.js:87:10:87:14 | proto | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | lib.js:83:14:83:25 | arguments[1] | library input |
|
| 286 | +| lib.js:108:3:108:10 | obj[one] | lib.js:104:13:104:24 | arguments[1] | lib.js:108:3:108:10 | obj[one] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | lib.js:104:13:104:24 | arguments[1] | library input | |
275 | 287 | | tst.js:8:5:8:17 | object[taint] | tst.js:5:24:5:37 | req.query.data | tst.js:8:5:8:17 | object[taint] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | user controlled input |
|
276 | 288 | | tst.js:9:5:9:17 | object[taint] | tst.js:5:24:5:37 | req.query.data | tst.js:9:5:9:17 | object[taint] | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | user controlled input |
|
277 | 289 | | tst.js:14:5:14:32 | unsafeG ... taint) | tst.js:5:24:5:37 | req.query.data | tst.js:14:5:14:32 | unsafeG ... taint) | This assignment may alter Object.prototype if a malicious '__proto__' string is injected from $@. | tst.js:5:24:5:37 | req.query.data | user controlled input |
|
|
0 commit comments