Asger F
|
4bac90252c
|
JS: Port HardcodedCredentials
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
f4d62c3225
|
JS: Port HttpToFileAccess
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
2935aac559
|
JS: Port FileAccessToHttp
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
8e95a90d03
|
JS: Port UntrustedDataToExternalAPI
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
d324e554f3
|
JS: Port DeepObjectResourceExhaustion
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
30f1fbc10d
|
JS: Port CorsMisconfigurationForCredentials
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
f14303acea
|
JS: Port ConditionalBypass
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
2296a273c4
|
JS: Port BuildArtifactLeak
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
85617c292e
|
JS: Port BrokenCryptoAlgorithm
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
7a1aead831
|
JS: Port ZipSlip
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
e9189f965f
|
JS: Port LogInjection
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
ae680e747b
|
JS: Port LoopBoundInjection
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
40d68cb4dc
|
JS: Port CleartextStorage
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
b8a6f81669
|
JS: Port CleartextLogging
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
a5c221fcfc
|
JS: Port PrototypePollutingMergeCall
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
adf7d5409d
|
JS: Port PrototypePollutingFunction
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
f1f45927b1
|
JS: Port PrototypePollutingAssignment
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
81d2721248
|
JS: Port ClientSideUrlRedirect
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
46fd727a55
|
JS: Port ServerSideUrlRedirect
|
2023-10-13 13:15:04 +02:00 |
|
Asger F
|
92816b1c9a
|
JS: Port ClientSideRequestForgery
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
b2216627be
|
JS: Port RequestForgery
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
d7b4e0c206
|
JS: Port ExceptionXss
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
cf5450dbd5
|
JS: Port XssThroughDom
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
5f05232e02
|
JS: Port StoredXss
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
46b90e51fc
|
JS: Port ReflectedXss
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
e091fdefa4
|
JS: Port DomBasedXss
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
547a8a958a
|
JS: Port SqlInjection
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
65e9706c8e
|
JS: Port TaintedPath
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
fcfab5238e
|
JS: Port CodeInjection
|
2023-10-13 13:15:03 +02:00 |
|
Asger F
|
17233a6749
|
JS: Port CommandInjection
|
2023-10-13 13:15:03 +02:00 |
|
amammad
|
6f73e9c3ba
|
revert for in additional steps
|
2023-10-10 22:12:37 +02:00 |
|
amammad
|
aff6f00450
|
comments improvement,separate module file, fix tests
|
2023-10-07 12:02:39 +02:00 |
|
amammad
|
5a49f6bb9b
|
fix tests
|
2023-10-06 22:10:57 +02:00 |
|
Max Schaefer
|
e722e3288f
|
Merge pull request #13771 from github/max-schaefer/server-side-url-redirect-help
JavaScript: Improve query help for `js/server-side-unvalidated-url-redirection`.
|
2023-09-13 13:20:48 +01:00 |
|
Max Schaefer
|
a9e81672f0
|
Make suggestion to replace example.com more explicit.
|
2023-09-12 16:54:05 +01:00 |
|
Max Schaefer
|
a02f373e79
|
Use better sanitiser.
|
2023-09-06 14:06:16 +01:00 |
|
Max Schaefer
|
87364137df
|
Use more sensible validator in example.
|
2023-08-21 15:14:01 +01:00 |
|
erik-krogh
|
0bce42410a
|
support arbitrary codepoints in NfaUtils.qll
|
2023-08-08 22:14:51 +02:00 |
|
erik-krogh
|
92db7b047c
|
escape unicode chars in the output for the ReDoS queries
|
2023-08-08 00:15:54 +02:00 |
|
Max Schaefer
|
7823ff968c
|
JavaScript: Improve query help for js/server-side-unvalidated-url-redirection.
|
2023-07-19 13:23:25 +01:00 |
|
Asger F
|
d57276ca35
|
Merge pull request #13719 from asgerf/js/barrier-inout
JS: Replace barrier edges with barrier nodes
|
2023-07-13 16:36:52 +02:00 |
|
Asger F
|
944a2ca825
|
JS: Replace ClearTextLogging::isSanitizerEdge with a node
|
2023-07-11 14:20:17 +02:00 |
|
Asger F
|
27085b1fd0
|
JS: Fix whitespace
|
2023-07-10 12:07:13 +02:00 |
|
Asger F
|
fe90146a16
|
JS: Add test for path.join with spread argument
|
2023-07-10 12:07:07 +02:00 |
|
Asger F
|
06bc0f6957
|
JS: Add test for fs/promises
|
2023-07-10 12:05:03 +02:00 |
|
Erik Krogh Kristensen
|
b2a60bf3d1
|
Merge pull request #13642 from erik-krogh/san-script
JS/RB: Fix FP in incomplete-multi-character-sanitization
|
2023-07-06 15:38:39 +02:00 |
|
erik-krogh
|
f9eee906cf
|
fix FP by requiring that the regular expression mention on of the chars important in the prefix
|
2023-07-01 20:30:09 +02:00 |
|
erik-krogh
|
bd400be6ec
|
add FP for incomplete-multi-char-sanitization
|
2023-07-01 20:28:31 +02:00 |
|
jorgectf
|
2ac334bf15
|
Adapt Webix modeling to support HTML use-cases
|
2023-06-28 15:26:30 +02:00 |
|
amammad
|
c7a7594821
|
merge all ql files into one
|
2023-06-27 01:56:23 +10:00 |
|