|
8 | 8 | | NoSQLCodeInjection.js:19:36:19:43 | req.body | |
9 | 9 | | NoSQLCodeInjection.js:19:36:19:43 | req.body | |
10 | 10 | | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | |
| 11 | +| NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | |
| 12 | +| NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | |
| 13 | +| NoSQLCodeInjection.js:22:36:22:43 | req.body | |
| 14 | +| NoSQLCodeInjection.js:22:36:22:43 | req.body | |
| 15 | +| NoSQLCodeInjection.js:22:36:22:48 | req.body.name | |
11 | 16 | | angularjs.js:10:22:10:29 | location | |
12 | 17 | | angularjs.js:10:22:10:29 | location | |
13 | 18 | | angularjs.js:10:22:10:36 | location.search | |
@@ -152,6 +157,10 @@ edges |
152 | 157 | | NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | |
153 | 158 | | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
154 | 159 | | NoSQLCodeInjection.js:19:36:19:48 | req.body.name | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | |
| 160 | +| NoSQLCodeInjection.js:22:36:22:43 | req.body | NoSQLCodeInjection.js:22:36:22:48 | req.body.name | |
| 161 | +| NoSQLCodeInjection.js:22:36:22:43 | req.body | NoSQLCodeInjection.js:22:36:22:48 | req.body.name | |
| 162 | +| NoSQLCodeInjection.js:22:36:22:48 | req.body.name | NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | |
| 163 | +| NoSQLCodeInjection.js:22:36:22:48 | req.body.name | NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | |
155 | 164 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
156 | 165 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
157 | 166 | | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | |
@@ -275,6 +284,7 @@ edges |
275 | 284 | #select |
276 | 285 | | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | $@ flows to here and is interpreted as code. | NoSQLCodeInjection.js:18:24:18:31 | req.body | User-provided value | |
277 | 286 | | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | $@ flows to here and is interpreted as code. | NoSQLCodeInjection.js:19:36:19:43 | req.body | User-provided value | |
| 287 | +| NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | NoSQLCodeInjection.js:22:36:22:43 | req.body | NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | $@ flows to here and is interpreted as code. | NoSQLCodeInjection.js:22:36:22:43 | req.body | User-provided value | |
278 | 288 | | angularjs.js:10:22:10:36 | location.search | angularjs.js:10:22:10:29 | location | angularjs.js:10:22:10:36 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:10:22:10:29 | location | User-provided value | |
279 | 289 | | angularjs.js:13:23:13:37 | location.search | angularjs.js:13:23:13:30 | location | angularjs.js:13:23:13:37 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:13:23:13:30 | location | User-provided value | |
280 | 290 | | angularjs.js:16:28:16:42 | location.search | angularjs.js:16:28:16:35 | location | angularjs.js:16:28:16:42 | location.search | $@ flows to here and is interpreted as code. | angularjs.js:16:28:16:35 | location | User-provided value | |
|
0 commit comments