|
120 | 120 | | string-manipulations.js:8:16:8:48 | documen ... mLeft() | string-manipulations.js:8:16:8:37 | documen ... on.href | string-manipulations.js:8:16:8:48 | documen ... mLeft() | Cross-site scripting vulnerability due to $@. | string-manipulations.js:8:16:8:37 | documen ... on.href | user-provided value | |
121 | 121 | | string-manipulations.js:9:16:9:58 | String. ... n.href) | string-manipulations.js:9:36:9:57 | documen ... on.href | string-manipulations.js:9:16:9:58 | String. ... n.href) | Cross-site scripting vulnerability due to $@. | string-manipulations.js:9:36:9:57 | documen ... on.href | user-provided value | |
122 | 122 | | string-manipulations.js:10:16:10:45 | String( ... n.href) | string-manipulations.js:10:23:10:44 | documen ... on.href | string-manipulations.js:10:16:10:45 | String( ... n.href) | Cross-site scripting vulnerability due to $@. | string-manipulations.js:10:23:10:44 | documen ... on.href | user-provided value | |
| 123 | +| string-manipulations.js:11:16:11:45 | escape( ... n.href) | string-manipulations.js:11:23:11:44 | documen ... on.href | string-manipulations.js:11:16:11:45 | escape( ... n.href) | Cross-site scripting vulnerability due to $@. | string-manipulations.js:11:23:11:44 | documen ... on.href | user-provided value | |
| 124 | +| string-manipulations.js:12:16:12:61 | escape( ... href))) | string-manipulations.js:12:37:12:58 | documen ... on.href | string-manipulations.js:12:16:12:61 | escape( ... href))) | Cross-site scripting vulnerability due to $@. | string-manipulations.js:12:37:12:58 | documen ... on.href | user-provided value | |
123 | 125 | | tainted-url-suffix-arguments.js:6:22:6:22 | y | tainted-url-suffix-arguments.js:11:17:11:36 | window.location.href | tainted-url-suffix-arguments.js:6:22:6:22 | y | Cross-site scripting vulnerability due to $@. | tainted-url-suffix-arguments.js:11:17:11:36 | window.location.href | user-provided value | |
124 | 126 | | tooltip.jsx:10:25:10:30 | source | tooltip.jsx:6:20:6:30 | window.name | tooltip.jsx:10:25:10:30 | source | Cross-site scripting vulnerability due to $@. | tooltip.jsx:6:20:6:30 | window.name | user-provided value | |
125 | 127 | | tooltip.jsx:11:25:11:30 | source | tooltip.jsx:6:20:6:30 | window.name | tooltip.jsx:11:25:11:30 | source | Cross-site scripting vulnerability due to $@. | tooltip.jsx:6:20:6:30 | window.name | user-provided value | |
@@ -490,6 +492,10 @@ edges |
490 | 492 | | string-manipulations.js:8:16:8:37 | documen ... on.href | string-manipulations.js:8:16:8:48 | documen ... mLeft() | provenance | | |
491 | 493 | | string-manipulations.js:9:36:9:57 | documen ... on.href | string-manipulations.js:9:16:9:58 | String. ... n.href) | provenance | | |
492 | 494 | | string-manipulations.js:10:23:10:44 | documen ... on.href | string-manipulations.js:10:16:10:45 | String( ... n.href) | provenance | | |
| 495 | +| string-manipulations.js:11:23:11:44 | documen ... on.href | string-manipulations.js:11:16:11:45 | escape( ... n.href) | provenance | | |
| 496 | +| string-manipulations.js:12:23:12:60 | escape( ... .href)) | string-manipulations.js:12:16:12:61 | escape( ... href))) | provenance | | |
| 497 | +| string-manipulations.js:12:30:12:59 | escape( ... n.href) | string-manipulations.js:12:23:12:60 | escape( ... .href)) | provenance | | |
| 498 | +| string-manipulations.js:12:37:12:58 | documen ... on.href | string-manipulations.js:12:30:12:59 | escape( ... n.href) | provenance | | |
493 | 499 | | tainted-url-suffix-arguments.js:3:17:3:17 | y | tainted-url-suffix-arguments.js:6:22:6:22 | y | provenance | | |
494 | 500 | | tainted-url-suffix-arguments.js:11:11:11:36 | url | tainted-url-suffix-arguments.js:12:17:12:19 | url | provenance | | |
495 | 501 | | tainted-url-suffix-arguments.js:11:17:11:36 | window.location.href | tainted-url-suffix-arguments.js:11:11:11:36 | url | provenance | | |
@@ -1116,6 +1122,12 @@ nodes |
1116 | 1122 | | string-manipulations.js:9:36:9:57 | documen ... on.href | semmle.label | documen ... on.href | |
1117 | 1123 | | string-manipulations.js:10:16:10:45 | String( ... n.href) | semmle.label | String( ... n.href) | |
1118 | 1124 | | string-manipulations.js:10:23:10:44 | documen ... on.href | semmle.label | documen ... on.href | |
| 1125 | +| string-manipulations.js:11:16:11:45 | escape( ... n.href) | semmle.label | escape( ... n.href) | |
| 1126 | +| string-manipulations.js:11:23:11:44 | documen ... on.href | semmle.label | documen ... on.href | |
| 1127 | +| string-manipulations.js:12:16:12:61 | escape( ... href))) | semmle.label | escape( ... href))) | |
| 1128 | +| string-manipulations.js:12:23:12:60 | escape( ... .href)) | semmle.label | escape( ... .href)) | |
| 1129 | +| string-manipulations.js:12:30:12:59 | escape( ... n.href) | semmle.label | escape( ... n.href) | |
| 1130 | +| string-manipulations.js:12:37:12:58 | documen ... on.href | semmle.label | documen ... on.href | |
1119 | 1131 | | tainted-url-suffix-arguments.js:3:17:3:17 | y | semmle.label | y | |
1120 | 1132 | | tainted-url-suffix-arguments.js:6:22:6:22 | y | semmle.label | y | |
1121 | 1133 | | tainted-url-suffix-arguments.js:11:11:11:36 | url | semmle.label | url | |
|
0 commit comments