|
62 | 62 | | dragAndDrop.ts:73:29:73:39 | droppedHtml | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | dragAndDrop.ts:73:29:73:39 | droppedHtml | Cross-site scripting vulnerability due to $@. | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | user-provided value | |
63 | 63 | | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | Cross-site scripting vulnerability due to $@. | event-handler-receiver.js:2:49:2:61 | location.href | user-provided value | |
64 | 64 | | express.js:6:15:6:33 | req.param("wobble") | express.js:6:15:6:33 | req.param("wobble") | express.js:6:15:6:33 | req.param("wobble") | Cross-site scripting vulnerability due to $@. | express.js:6:15:6:33 | req.param("wobble") | user-provided value | |
| 65 | +| firebase-client.js:7:59:7:65 | x.val() | firebase-client.js:7:59:7:65 | x.val() | firebase-client.js:7:59:7:65 | x.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:7:59:7:65 | x.val() | user-provided value | |
| 66 | +| firebase-client.js:8:59:8:79 | x.expor ... message | firebase-client.js:8:59:8:71 | x.exportVal() | firebase-client.js:8:59:8:79 | x.expor ... message | Cross-site scripting vulnerability due to $@. | firebase-client.js:8:59:8:71 | x.exportVal() | user-provided value | |
| 67 | +| firebase-client.js:10:63:10:82 | parentSnapshot.val() | firebase-client.js:10:63:10:82 | parentSnapshot.val() | firebase-client.js:10:63:10:82 | parentSnapshot.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:10:63:10:82 | parentSnapshot.val() | user-provided value | |
| 68 | +| firebase-client.js:14:54:14:70 | bioSnapshot.val() | firebase-client.js:14:54:14:70 | bioSnapshot.val() | firebase-client.js:14:54:14:70 | bioSnapshot.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:14:54:14:70 | bioSnapshot.val() | user-provided value | |
| 69 | +| firebase-client.js:19:56:19:84 | `<div>$ ... </div>` | firebase-client.js:18:20:18:38 | childSnapshot.val() | firebase-client.js:19:56:19:84 | `<div>$ ... </div>` | Cross-site scripting vulnerability due to $@. | firebase-client.js:18:20:18:38 | childSnapshot.val() | user-provided value | |
| 70 | +| firebase-client.js:25:59:25:65 | x.val() | firebase-client.js:25:59:25:65 | x.val() | firebase-client.js:25:59:25:65 | x.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:25:59:25:65 | x.val() | user-provided value | |
| 71 | +| firebase-client.js:26:59:26:79 | x.expor ... message | firebase-client.js:26:59:26:71 | x.exportVal() | firebase-client.js:26:59:26:79 | x.expor ... message | Cross-site scripting vulnerability due to $@. | firebase-client.js:26:59:26:71 | x.exportVal() | user-provided value | |
| 72 | +| firebase-client.js:28:63:28:82 | parentSnapshot.val() | firebase-client.js:28:63:28:82 | parentSnapshot.val() | firebase-client.js:28:63:28:82 | parentSnapshot.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:28:63:28:82 | parentSnapshot.val() | user-provided value | |
| 73 | +| firebase-client.js:33:52:33:65 | snapshot.val() | firebase-client.js:33:52:33:65 | snapshot.val() | firebase-client.js:33:52:33:65 | snapshot.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:33:52:33:65 | snapshot.val() | user-provided value | |
| 74 | +| firebase-client.js:38:56:38:67 | userData.bio | firebase-client.js:37:22:37:35 | snapshot.val() | firebase-client.js:38:56:38:67 | userData.bio | Cross-site scripting vulnerability due to $@. | firebase-client.js:37:22:37:35 | snapshot.val() | user-provided value | |
| 75 | +| firebase-client.js:44:55:44:74 | parentSnapshot.val() | firebase-client.js:44:55:44:74 | parentSnapshot.val() | firebase-client.js:44:55:44:74 | parentSnapshot.val() | Cross-site scripting vulnerability due to $@. | firebase-client.js:44:55:44:74 | parentSnapshot.val() | user-provided value | |
65 | 76 | | jquery.js:7:5:7:34 | "<div i ... + "\\">" | jquery.js:2:17:2:40 | documen ... .search | jquery.js:7:5:7:34 | "<div i ... + "\\">" | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value | |
66 | 77 | | jquery.js:8:18:8:34 | "XSS: " + tainted | jquery.js:2:17:2:40 | documen ... .search | jquery.js:8:18:8:34 | "XSS: " + tainted | Cross-site scripting vulnerability due to $@. | jquery.js:2:17:2:40 | documen ... .search | user-provided value | |
67 | 78 | | jquery.js:10:5:10:40 | "<b>" + ... "</b>" | jquery.js:10:13:10:20 | location | jquery.js:10:5:10:40 | "<b>" + ... "</b>" | Cross-site scripting vulnerability due to $@. | jquery.js:10:13:10:20 | location | user-provided value | |
@@ -352,6 +363,15 @@ edges |
352 | 363 | | dragAndDrop.ts:71:27:71:61 | e.dataT ... /html') | dragAndDrop.ts:71:13:71:61 | droppedHtml | provenance | | |
353 | 364 | | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | provenance | | |
354 | 365 | | event-handler-receiver.js:2:49:2:61 | location.href | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | provenance | Config | |
| 366 | +| firebase-client.js:8:59:8:71 | x.exportVal() | firebase-client.js:8:59:8:79 | x.expor ... message | provenance | | |
| 367 | +| firebase-client.js:18:13:18:38 | data | firebase-client.js:19:64:19:67 | data | provenance | | |
| 368 | +| firebase-client.js:18:20:18:38 | childSnapshot.val() | firebase-client.js:18:13:18:38 | data | provenance | | |
| 369 | +| firebase-client.js:19:64:19:67 | data | firebase-client.js:19:64:19:76 | data.username | provenance | | |
| 370 | +| firebase-client.js:19:64:19:76 | data.username | firebase-client.js:19:56:19:84 | `<div>$ ... </div>` | provenance | | |
| 371 | +| firebase-client.js:26:59:26:71 | x.exportVal() | firebase-client.js:26:59:26:79 | x.expor ... message | provenance | | |
| 372 | +| firebase-client.js:37:11:37:35 | userData | firebase-client.js:38:56:38:63 | userData | provenance | | |
| 373 | +| firebase-client.js:37:22:37:35 | snapshot.val() | firebase-client.js:37:11:37:35 | userData | provenance | | |
| 374 | +| firebase-client.js:38:56:38:63 | userData | firebase-client.js:38:56:38:67 | userData.bio | provenance | | |
355 | 375 | | jquery.js:2:7:2:40 | tainted | jquery.js:4:5:4:11 | tainted | provenance | | |
356 | 376 | | jquery.js:2:7:2:40 | tainted | jquery.js:5:13:5:19 | tainted | provenance | | |
357 | 377 | | jquery.js:2:7:2:40 | tainted | jquery.js:6:11:6:17 | tainted | provenance | | |
@@ -954,6 +974,26 @@ nodes |
954 | 974 | | event-handler-receiver.js:2:31:2:83 | '<h2><a ... ></h2>' | semmle.label | '<h2><a ... ></h2>' | |
955 | 975 | | event-handler-receiver.js:2:49:2:61 | location.href | semmle.label | location.href | |
956 | 976 | | express.js:6:15:6:33 | req.param("wobble") | semmle.label | req.param("wobble") | |
| 977 | +| firebase-client.js:7:59:7:65 | x.val() | semmle.label | x.val() | |
| 978 | +| firebase-client.js:8:59:8:71 | x.exportVal() | semmle.label | x.exportVal() | |
| 979 | +| firebase-client.js:8:59:8:79 | x.expor ... message | semmle.label | x.expor ... message | |
| 980 | +| firebase-client.js:10:63:10:82 | parentSnapshot.val() | semmle.label | parentSnapshot.val() | |
| 981 | +| firebase-client.js:14:54:14:70 | bioSnapshot.val() | semmle.label | bioSnapshot.val() | |
| 982 | +| firebase-client.js:18:13:18:38 | data | semmle.label | data | |
| 983 | +| firebase-client.js:18:20:18:38 | childSnapshot.val() | semmle.label | childSnapshot.val() | |
| 984 | +| firebase-client.js:19:56:19:84 | `<div>$ ... </div>` | semmle.label | `<div>$ ... </div>` | |
| 985 | +| firebase-client.js:19:64:19:67 | data | semmle.label | data | |
| 986 | +| firebase-client.js:19:64:19:76 | data.username | semmle.label | data.username | |
| 987 | +| firebase-client.js:25:59:25:65 | x.val() | semmle.label | x.val() | |
| 988 | +| firebase-client.js:26:59:26:71 | x.exportVal() | semmle.label | x.exportVal() | |
| 989 | +| firebase-client.js:26:59:26:79 | x.expor ... message | semmle.label | x.expor ... message | |
| 990 | +| firebase-client.js:28:63:28:82 | parentSnapshot.val() | semmle.label | parentSnapshot.val() | |
| 991 | +| firebase-client.js:33:52:33:65 | snapshot.val() | semmle.label | snapshot.val() | |
| 992 | +| firebase-client.js:37:11:37:35 | userData | semmle.label | userData | |
| 993 | +| firebase-client.js:37:22:37:35 | snapshot.val() | semmle.label | snapshot.val() | |
| 994 | +| firebase-client.js:38:56:38:63 | userData | semmle.label | userData | |
| 995 | +| firebase-client.js:38:56:38:67 | userData.bio | semmle.label | userData.bio | |
| 996 | +| firebase-client.js:44:55:44:74 | parentSnapshot.val() | semmle.label | parentSnapshot.val() | |
957 | 997 | | jquery.js:2:7:2:40 | tainted | semmle.label | tainted | |
958 | 998 | | jquery.js:2:17:2:40 | documen ... .search | semmle.label | documen ... .search | |
959 | 999 | | jquery.js:4:5:4:11 | tainted | semmle.label | tainted | |
|
0 commit comments