|
| 1 | +nodes |
| 2 | +| bad-code-sanitization.js:2:12:2:90 | /^[_$a- ... key)}]` | |
| 3 | +| bad-code-sanitization.js:2:65:2:90 | `[${JSO ... key)}]` | |
| 4 | +| bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | |
| 5 | +| bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | |
| 6 | +| bad-code-sanitization.js:6:11:6:25 | statements | |
| 7 | +| bad-code-sanitization.js:6:24:6:25 | [] | |
| 8 | +| bad-code-sanitization.js:7:21:7:70 | `${name ... key])}` | |
| 9 | +| bad-code-sanitization.js:7:31:7:43 | safeProp(key) | |
| 10 | +| bad-code-sanitization.js:8:27:8:36 | statements | |
| 11 | +| bad-code-sanitization.js:8:27:8:46 | statements.join(';') | |
| 12 | +| bad-code-sanitization.js:8:27:8:46 | statements.join(';') | |
| 13 | +| bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | |
| 14 | +| bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | |
| 15 | +| bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | |
| 16 | +| bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | |
| 17 | +| bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | |
| 18 | +| bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | |
| 19 | +| bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | |
| 20 | +| bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | |
| 21 | +| bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | |
| 22 | +| bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | |
| 23 | +| bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | |
| 24 | +| bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | |
| 25 | +edges |
| 26 | +| bad-code-sanitization.js:2:12:2:90 | /^[_$a- ... key)}]` | bad-code-sanitization.js:7:31:7:43 | safeProp(key) | |
| 27 | +| bad-code-sanitization.js:2:65:2:90 | `[${JSO ... key)}]` | bad-code-sanitization.js:2:12:2:90 | /^[_$a- ... key)}]` | |
| 28 | +| bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | bad-code-sanitization.js:2:65:2:90 | `[${JSO ... key)}]` | |
| 29 | +| bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | bad-code-sanitization.js:2:65:2:90 | `[${JSO ... key)}]` | |
| 30 | +| bad-code-sanitization.js:6:11:6:25 | statements | bad-code-sanitization.js:8:27:8:36 | statements | |
| 31 | +| bad-code-sanitization.js:6:24:6:25 | [] | bad-code-sanitization.js:6:11:6:25 | statements | |
| 32 | +| bad-code-sanitization.js:7:21:7:70 | `${name ... key])}` | bad-code-sanitization.js:6:24:6:25 | [] | |
| 33 | +| bad-code-sanitization.js:7:31:7:43 | safeProp(key) | bad-code-sanitization.js:7:21:7:70 | `${name ... key])}` | |
| 34 | +| bad-code-sanitization.js:8:27:8:36 | statements | bad-code-sanitization.js:8:27:8:46 | statements.join(';') | |
| 35 | +| bad-code-sanitization.js:8:27:8:36 | statements | bad-code-sanitization.js:8:27:8:46 | statements.join(';') | |
| 36 | +| bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | |
| 37 | +| bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | |
| 38 | +| bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | |
| 39 | +| bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | |
| 40 | +#select |
| 41 | +| bad-code-sanitization.js:8:27:8:46 | statements.join(';') | bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | bad-code-sanitization.js:8:27:8:46 | statements.join(';') | $@ flows to here and is used to construct code. | bad-code-sanitization.js:2:69:2:87 | JSON.stringify(key) | Improperly sanitized value | |
| 42 | +| bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | $@ flows to here and is used to construct code. | bad-code-sanitization.js:15:44:15:63 | htmlescape(pathname) | Improperly sanitized value | |
| 43 | +| bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | $@ flows to here and is used to construct code. | bad-code-sanitization.js:19:27:19:47 | JSON.st ... (input) | Improperly sanitized value | |
| 44 | +| bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | $@ flows to here and is used to construct code. | bad-code-sanitization.js:40:23:40:43 | JSON.st ... (input) | Improperly sanitized value | |
| 45 | +| bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | $@ flows to here and is used to construct code. | bad-code-sanitization.js:44:22:44:42 | JSON.st ... (input) | Improperly sanitized value | |
0 commit comments