Refactor SqlInjectionQuery

This commit is contained in:
Ed Minnix
2023-03-21 20:58:39 -04:00
parent fec80973a9
commit bf5f82bb78
2 changed files with 30 additions and 5 deletions

View File

@@ -15,8 +15,9 @@
import java
import semmle.code.java.dataflow.FlowSources
import semmle.code.java.security.SqlInjectionQuery
import DataFlow::PathGraph
import QueryInjectionFlow::PathGraph
from QueryInjectionSink query, DataFlow::PathNode source, DataFlow::PathNode sink
from
QueryInjectionSink query, QueryInjectionFlow::PathNode source, QueryInjectionFlow::PathNode sink
where queryTaintedBy(query, source, sink)
select query, source, sink, "This query depends on a $@.", source.getNode(), "user-provided value"