|
22 | 22 | | express.js:135:23:135:37 | req.params.user | |
23 | 23 | | express.js:136:16:136:36 | 'u' + r ... ms.user | |
24 | 24 | | express.js:136:22:136:36 | req.params.user | |
| 25 | +| koa.js:6:6:6:27 | url | |
| 26 | +| koa.js:6:12:6:27 | ctx.query.target | |
| 27 | +| koa.js:7:15:7:17 | url | |
| 28 | +| koa.js:8:15:8:26 | `${url}${x}` | |
| 29 | +| koa.js:8:18:8:20 | url | |
| 30 | +| koa.js:14:16:14:18 | url | |
25 | 31 | | node.js:6:7:6:52 | target | |
26 | 32 | | node.js:6:16:6:39 | url.par ... , true) | |
27 | 33 | | node.js:6:16:6:45 | url.par ... ).query | |
|
60 | 66 | | express.js:134:22:134:36 | req.params.user | express.js:134:16:134:36 | '/' + r ... ms.user | |
61 | 67 | | express.js:135:23:135:37 | req.params.user | express.js:135:16:135:37 | '//' + ... ms.user | |
62 | 68 | | express.js:136:22:136:36 | req.params.user | express.js:136:16:136:36 | 'u' + r ... ms.user | |
| 69 | +| koa.js:6:6:6:27 | url | koa.js:7:15:7:17 | url | |
| 70 | +| koa.js:6:6:6:27 | url | koa.js:8:18:8:20 | url | |
| 71 | +| koa.js:6:6:6:27 | url | koa.js:10:40:10:42 | url | |
| 72 | +| koa.js:6:6:6:27 | url | koa.js:10:40:10:42 | url | |
| 73 | +| koa.js:6:6:6:27 | url | koa.js:10:51:10:51 | url | |
| 74 | +| koa.js:6:6:6:27 | url | koa.js:11:6:11:8 | url | |
| 75 | +| koa.js:6:6:6:27 | url | koa.js:14:16:14:18 | url | |
| 76 | +| koa.js:6:12:6:27 | ctx.query.target | koa.js:6:6:6:27 | url | |
| 77 | +| koa.js:8:18:8:20 | url | koa.js:8:15:8:26 | `${url}${x}` | |
| 78 | +| koa.js:10:40:10:42 | url | koa.js:10:51:10:51 | url | |
| 79 | +| koa.js:10:40:10:42 | url | koa.js:10:51:10:51 | url | |
| 80 | +| koa.js:10:40:10:42 | url | koa.js:11:6:11:8 | url | |
| 81 | +| koa.js:10:40:10:42 | url | koa.js:11:6:11:8 | url | |
| 82 | +| koa.js:10:40:10:42 | url | koa.js:14:16:14:18 | url | |
| 83 | +| koa.js:10:40:10:42 | url | koa.js:14:16:14:18 | url | |
| 84 | +| koa.js:10:51:10:51 | url | koa.js:11:6:11:8 | url | |
| 85 | +| koa.js:10:51:10:51 | url | koa.js:14:16:14:18 | url | |
| 86 | +| koa.js:11:6:11:8 | url | koa.js:14:16:14:18 | url | |
63 | 87 | | node.js:6:7:6:52 | target | node.js:7:34:7:39 | target | |
64 | 88 | | node.js:6:16:6:39 | url.par ... , true) | node.js:6:16:6:45 | url.par ... ).query | |
65 | 89 | | node.js:6:16:6:45 | url.par ... ).query | node.js:6:16:6:52 | url.par ... .target | |
|
95 | 119 | | express.js:134:16:134:36 | '/' + r ... ms.user | express.js:134:22:134:36 | req.params.user | express.js:134:16:134:36 | '/' + r ... ms.user | Untrusted URL redirection due to $@. | express.js:134:22:134:36 | req.params.user | user-provided value | |
96 | 120 | | express.js:135:16:135:37 | '//' + ... ms.user | express.js:135:23:135:37 | req.params.user | express.js:135:16:135:37 | '//' + ... ms.user | Untrusted URL redirection due to $@. | express.js:135:23:135:37 | req.params.user | user-provided value | |
97 | 121 | | express.js:136:16:136:36 | 'u' + r ... ms.user | express.js:136:22:136:36 | req.params.user | express.js:136:16:136:36 | 'u' + r ... ms.user | Untrusted URL redirection due to $@. | express.js:136:22:136:36 | req.params.user | user-provided value | |
| 122 | +| koa.js:7:15:7:17 | url | koa.js:6:12:6:27 | ctx.query.target | koa.js:7:15:7:17 | url | Untrusted URL redirection due to $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value | |
| 123 | +| koa.js:8:15:8:26 | `${url}${x}` | koa.js:6:12:6:27 | ctx.query.target | koa.js:8:15:8:26 | `${url}${x}` | Untrusted URL redirection due to $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value | |
| 124 | +| koa.js:14:16:14:18 | url | koa.js:6:12:6:27 | ctx.query.target | koa.js:14:16:14:18 | url | Untrusted URL redirection due to $@. | koa.js:6:12:6:27 | ctx.query.target | user-provided value | |
98 | 125 | | node.js:7:34:7:39 | target | node.js:6:26:6:32 | req.url | node.js:7:34:7:39 | target | Untrusted URL redirection due to $@. | node.js:6:26:6:32 | req.url | user-provided value | |
99 | 126 | | node.js:15:34:15:45 | '/' + target | node.js:11:26:11:32 | req.url | node.js:15:34:15:45 | '/' + target | Untrusted URL redirection due to $@. | node.js:11:26:11:32 | req.url | user-provided value | |
100 | 127 | | node.js:32:34:32:55 | target ... =" + me | node.js:29:26:29:32 | req.url | node.js:32:34:32:55 | target ... =" + me | Untrusted URL redirection due to $@. | node.js:29:26:29:32 | req.url | user-provided value | |
|
0 commit comments