|
|
|
|
@@ -296,6 +296,15 @@ nodes
|
|
|
|
|
| mongooseModelClient.js:12:22:12:29 | req.body |
|
|
|
|
|
| mongooseModelClient.js:12:22:12:29 | req.body |
|
|
|
|
|
| mongooseModelClient.js:12:22:12:32 | req.body.id |
|
|
|
|
|
| mysql.js:6:9:6:31 | temp |
|
|
|
|
|
| mysql.js:6:16:6:31 | req.params.value |
|
|
|
|
|
| mysql.js:6:16:6:31 | req.params.value |
|
|
|
|
|
| mysql.js:15:18:15:65 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:15:18:15:65 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:15:62:15:65 | temp |
|
|
|
|
|
| mysql.js:19:26:19:73 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:19:26:19:73 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:19:70:19:73 | temp |
|
|
|
|
|
| pg-promise-types.ts:7:9:7:28 | taint |
|
|
|
|
|
| pg-promise-types.ts:7:17:7:28 | req.params.x |
|
|
|
|
|
| pg-promise-types.ts:7:17:7:28 | req.params.x |
|
|
|
|
|
@@ -792,6 +801,14 @@ edges
|
|
|
|
|
| mongooseModelClient.js:12:22:12:29 | req.body | mongooseModelClient.js:12:22:12:32 | req.body.id |
|
|
|
|
|
| mongooseModelClient.js:12:22:12:32 | req.body.id | mongooseModelClient.js:12:16:12:34 | { id: req.body.id } |
|
|
|
|
|
| mongooseModelClient.js:12:22:12:32 | req.body.id | mongooseModelClient.js:12:16:12:34 | { id: req.body.id } |
|
|
|
|
|
| mysql.js:6:9:6:31 | temp | mysql.js:15:62:15:65 | temp |
|
|
|
|
|
| mysql.js:6:9:6:31 | temp | mysql.js:19:70:19:73 | temp |
|
|
|
|
|
| mysql.js:6:16:6:31 | req.params.value | mysql.js:6:9:6:31 | temp |
|
|
|
|
|
| mysql.js:6:16:6:31 | req.params.value | mysql.js:6:9:6:31 | temp |
|
|
|
|
|
| mysql.js:15:62:15:65 | temp | mysql.js:15:18:15:65 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:15:62:15:65 | temp | mysql.js:15:18:15:65 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:19:70:19:73 | temp | mysql.js:19:26:19:73 | 'SELECT ... + temp |
|
|
|
|
|
| mysql.js:19:70:19:73 | temp | mysql.js:19:26:19:73 | 'SELECT ... + temp |
|
|
|
|
|
| pg-promise-types.ts:7:9:7:28 | taint | pg-promise-types.ts:8:17:8:21 | taint |
|
|
|
|
|
| pg-promise-types.ts:7:9:7:28 | taint | pg-promise-types.ts:8:17:8:21 | taint |
|
|
|
|
|
| pg-promise-types.ts:7:17:7:28 | req.params.x | pg-promise-types.ts:7:9:7:28 | taint |
|
|
|
|
|
@@ -978,6 +995,8 @@ edges
|
|
|
|
|
| mongooseJsonParse.js:23:19:23:23 | query | mongooseJsonParse.js:20:30:20:43 | req.query.data | mongooseJsonParse.js:23:19:23:23 | query | This query depends on $@. | mongooseJsonParse.js:20:30:20:43 | req.query.data | a user-provided value |
|
|
|
|
|
| mongooseModelClient.js:11:16:11:24 | { id: v } | mongooseModelClient.js:10:22:10:29 | req.body | mongooseModelClient.js:11:16:11:24 | { id: v } | This query depends on $@. | mongooseModelClient.js:10:22:10:29 | req.body | a user-provided value |
|
|
|
|
|
| mongooseModelClient.js:12:16:12:34 | { id: req.body.id } | mongooseModelClient.js:12:22:12:29 | req.body | mongooseModelClient.js:12:16:12:34 | { id: req.body.id } | This query depends on $@. | mongooseModelClient.js:12:22:12:29 | req.body | a user-provided value |
|
|
|
|
|
| mysql.js:15:18:15:65 | 'SELECT ... + temp | mysql.js:6:16:6:31 | req.params.value | mysql.js:15:18:15:65 | 'SELECT ... + temp | This query depends on $@. | mysql.js:6:16:6:31 | req.params.value | a user-provided value |
|
|
|
|
|
| mysql.js:19:26:19:73 | 'SELECT ... + temp | mysql.js:6:16:6:31 | req.params.value | mysql.js:19:26:19:73 | 'SELECT ... + temp | This query depends on $@. | mysql.js:6:16:6:31 | req.params.value | a user-provided value |
|
|
|
|
|
| pg-promise-types.ts:8:17:8:21 | taint | pg-promise-types.ts:7:17:7:28 | req.params.x | pg-promise-types.ts:8:17:8:21 | taint | This query depends on $@. | pg-promise-types.ts:7:17:7:28 | req.params.x | a user-provided value |
|
|
|
|
|
| pg-promise.js:9:10:9:14 | query | pg-promise.js:7:16:7:34 | req.params.category | pg-promise.js:9:10:9:14 | query | This query depends on $@. | pg-promise.js:7:16:7:34 | req.params.category | a user-provided value |
|
|
|
|
|
| pg-promise.js:10:11:10:15 | query | pg-promise.js:7:16:7:34 | req.params.category | pg-promise.js:10:11:10:15 | query | This query depends on $@. | pg-promise.js:7:16:7:34 | req.params.category | a user-provided value |
|
|
|
|
|
|