|
13 | 13 | | CommandInjection.rb:83:14:83:34 | "echo #{...}" | CommandInjection.rb:82:23:82:33 | blah_number | CommandInjection.rb:83:14:83:34 | "echo #{...}" | This command depends on a $@. | CommandInjection.rb:82:23:82:33 | blah_number | user-provided value | |
14 | 14 | | CommandInjection.rb:92:14:92:39 | "echo #{...}" | CommandInjection.rb:92:22:92:37 | ...[...] | CommandInjection.rb:92:14:92:39 | "echo #{...}" | This command depends on a $@. | CommandInjection.rb:92:22:92:37 | ...[...] | user-provided value | |
15 | 15 | | CommandInjection.rb:105:16:105:28 | "cat #{...}" | CommandInjection.rb:104:16:104:21 | call to params | CommandInjection.rb:105:16:105:28 | "cat #{...}" | This command depends on a $@. | CommandInjection.rb:104:16:104:21 | call to params | user-provided value | |
| 16 | +| CommandInjection.rb:107:16:107:40 | "cat #{...}" | CommandInjection.rb:104:16:104:21 | call to params | CommandInjection.rb:107:16:107:40 | "cat #{...}" | This command depends on a $@. | CommandInjection.rb:104:16:104:21 | call to params | user-provided value | |
16 | 17 | | CommandInjection.rb:112:33:112:44 | ...[...] | CommandInjection.rb:112:33:112:38 | call to params | CommandInjection.rb:112:33:112:44 | ...[...] | This command depends on a $@. | CommandInjection.rb:112:33:112:38 | call to params | user-provided value | |
17 | 18 | | CommandInjection.rb:114:41:114:56 | "#{...}" | CommandInjection.rb:114:44:114:49 | call to params | CommandInjection.rb:114:41:114:56 | "#{...}" | This command depends on a $@. | CommandInjection.rb:114:44:114:49 | call to params | user-provided value | |
18 | 19 | edges |
|
36 | 37 | | CommandInjection.rb:82:23:82:33 | blah_number | CommandInjection.rb:83:14:83:34 | "echo #{...}" | provenance | AdditionalTaintStep | |
37 | 38 | | CommandInjection.rb:92:22:92:37 | ...[...] | CommandInjection.rb:92:14:92:39 | "echo #{...}" | provenance | AdditionalTaintStep | |
38 | 39 | | CommandInjection.rb:104:9:104:12 | file | CommandInjection.rb:105:16:105:28 | "cat #{...}" | provenance | AdditionalTaintStep | |
| 40 | +| CommandInjection.rb:104:9:104:12 | file | CommandInjection.rb:107:23:107:26 | file | provenance | | |
39 | 41 | | CommandInjection.rb:104:16:104:21 | call to params | CommandInjection.rb:104:16:104:28 | ...[...] | provenance | | |
40 | 42 | | CommandInjection.rb:104:16:104:28 | ...[...] | CommandInjection.rb:104:9:104:12 | file | provenance | | |
| 43 | +| CommandInjection.rb:107:23:107:26 | file | CommandInjection.rb:107:23:107:38 | call to shellescape | provenance | | |
| 44 | +| CommandInjection.rb:107:23:107:38 | call to shellescape | CommandInjection.rb:107:16:107:40 | "cat #{...}" | provenance | AdditionalTaintStep | |
41 | 45 | | CommandInjection.rb:112:33:112:38 | call to params | CommandInjection.rb:112:33:112:44 | ...[...] | provenance | Sink:MaD:1 | |
42 | 46 | | CommandInjection.rb:114:44:114:49 | call to params | CommandInjection.rb:114:44:114:54 | ...[...] | provenance | | |
43 | 47 | | CommandInjection.rb:114:44:114:54 | ...[...] | CommandInjection.rb:114:41:114:56 | "#{...}" | provenance | AdditionalTaintStep Sink:MaD:2 | |
|
74 | 78 | | CommandInjection.rb:104:16:104:21 | call to params | semmle.label | call to params | |
75 | 79 | | CommandInjection.rb:104:16:104:28 | ...[...] | semmle.label | ...[...] | |
76 | 80 | | CommandInjection.rb:105:16:105:28 | "cat #{...}" | semmle.label | "cat #{...}" | |
| 81 | +| CommandInjection.rb:107:16:107:40 | "cat #{...}" | semmle.label | "cat #{...}" | |
| 82 | +| CommandInjection.rb:107:23:107:26 | file | semmle.label | file | |
| 83 | +| CommandInjection.rb:107:23:107:38 | call to shellescape | semmle.label | call to shellescape | |
77 | 84 | | CommandInjection.rb:112:33:112:38 | call to params | semmle.label | call to params | |
78 | 85 | | CommandInjection.rb:112:33:112:44 | ...[...] | semmle.label | ...[...] | |
79 | 86 | | CommandInjection.rb:114:41:114:56 | "#{...}" | semmle.label | "#{...}" | |
80 | 87 | | CommandInjection.rb:114:44:114:49 | call to params | semmle.label | call to params | |
81 | 88 | | CommandInjection.rb:114:44:114:54 | ...[...] | semmle.label | ...[...] | |
82 | 89 | subpaths |
| 90 | +testFailures |
| 91 | +| CommandInjection.rb:107:16:107:40 | "cat #{...}" | Unexpected result: Alert | |
0 commit comments