jorgectf
|
bf68495102
|
Polish FlaskMail qldocs
|
2021-10-28 14:21:43 +02:00 |
|
jorgectf
|
c9634f3c6f
|
Fix getFlaskMailArgument()
|
2021-10-28 13:54:14 +02:00 |
|
jorgectf
|
4c2a4226ef
|
Merge remote-tracking branch 'origin/main' into jty/python/emailInjection
|
2021-10-28 13:26:57 +02:00 |
|
jorgectf
|
3dec222922
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/jwt-queries
|
2021-10-28 13:11:46 +02:00 |
|
jorgectf
|
7069f45864
|
Polish documentation
|
2021-10-28 13:09:28 +02:00 |
|
Rasmus Wriedt Larsen
|
58bc1102e5
|
Merge branch 'main' into jorgectf/python/deserialization
|
2021-10-28 12:31:34 +02:00 |
|
jorgectf
|
cf9e9f9dd4
|
Add cookie injection query missing proper tests
|
2021-10-28 10:28:45 +02:00 |
|
jorgectf
|
5dc1ad6f8a
|
Polish .ql
|
2021-10-28 09:25:47 +02:00 |
|
jorgectf
|
48c3c3d8a8
|
Broaden scope
|
2021-10-27 21:00:50 +02:00 |
|
jorgectf
|
28ec8c9dee
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/insecure-cookie
|
2021-10-27 19:00:55 +02:00 |
|
jorgectf
|
350cbb4c5d
|
Polish qhelp and libraries
|
2021-10-27 18:47:19 +02:00 |
|
Rasmus Lerchedahl Petersen
|
fed6a97eb8
|
Python: Promote ReDoS queries
|
2021-10-27 11:03:57 +02:00 |
|
jorgectf
|
14c50e993b
|
Add django GET.get RFS
|
2021-10-16 13:10:48 +02:00 |
|
jorgectf
|
45146bc798
|
Merge branch 'main' into jorgectf/python/headerInjection
|
2021-10-16 12:46:57 +02:00 |
|
jorgectf
|
2db1ffef1e
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/headerInjection
|
2021-10-16 10:40:52 +02:00 |
|
jorgectf
|
f1a73e3009
|
Merge branch 'jorgectf/python/deserialization' of https://github.com/jorgectf/codeql into jorgectf/python/deserialization
|
2021-10-16 10:07:13 +02:00 |
|
jorgectf
|
c2046f1777
|
Improve readability for xmlDom()
|
2021-10-16 10:07:11 +02:00 |
|
Jorge
|
be424704a6
|
Apply suggestions from code review
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com>
|
2021-10-16 10:04:50 +02:00 |
|
jorgectf
|
320a00be31
|
Delete simple API::Nodes
|
2021-10-16 10:02:43 +02:00 |
|
jorgectf
|
5b66a15de3
|
Extend mayBeDangerous() QLDoc
|
2021-10-16 09:57:28 +02:00 |
|
Rasmus Lerchedahl Petersen
|
61008fd3d0
|
Merge branch 'main' of github.com:github/codeql into python/promote-regex-injection
|
2021-10-12 11:28:12 +02:00 |
|
yoff
|
43f7eede0b
|
Merge pull request #6182 from haby0/python/LogInjection
Python: CWE-117 Log injection
|
2021-10-12 10:54:45 +02:00 |
|
haby0
|
d52f95d24d
|
Auto Formatting
|
2021-10-12 09:36:44 +08:00 |
|
yoff
|
0629ce00de
|
Merge pull request #6214 from haby0/python/ClientSuppliedIpUsedInSecurityCheck
[Python] CWE-348: Client supplied ip used in security check
|
2021-10-11 16:38:04 +02:00 |
|
haby0
|
538bf7c321
|
Update python/ql/src/experimental/Security/CWE-348/ClientSuppliedIpUsedInSecurityCheck.ql
Co-authored-by: yoff <lerchedahl@gmail.com>
|
2021-10-07 19:44:25 +08:00 |
|
haby0
|
a17b0d4e5c
|
Modify Sanitizer
|
2021-10-05 17:12:04 +08:00 |
|
Rasmus Wriedt Larsen
|
e472814ddd
|
Python: Fix XXE qhelp
|
2021-09-28 17:02:39 +02:00 |
|
Rasmus Wriedt Larsen
|
9c286a1b50
|
Python: fix name of .qhelp file
|
2021-09-28 16:57:46 +02:00 |
|
Rasmus Wriedt Larsen
|
67fddda6d2
|
Merge branch 'main' into jorgectf/python/deserialization
|
2021-09-28 16:49:33 +02:00 |
|
Rasmus Wriedt Larsen
|
547cbb6322
|
Merge pull request #6331 from porcupineyhairs/pythonXpath
Python : Improve Xpath Injection Query
|
2021-09-24 18:11:08 +02:00 |
|
Rasmus Wriedt Larsen
|
26d2fbd217
|
Python: Fix new XPath injection query
Fixes the typo `ETXpath` => `ETXPath`
|
2021-09-24 15:11:34 +02:00 |
|
Rasmus Wriedt Larsen
|
913a679ef5
|
Python: Replace old XPath injection query
|
2021-09-24 15:10:41 +02:00 |
|
Rasmus Wriedt Larsen
|
c9640ffdbc
|
Python: Minor adjustments to XPath Injection
|
2021-09-24 15:02:39 +02:00 |
|
Rasmus Wriedt Larsen
|
289660067c
|
Merge branch 'main' into pythonXpath
|
2021-09-24 13:53:38 +02:00 |
|
haby0
|
9b969e15fc
|
Modify according to @yoff suggestion
|
2021-09-24 12:56:10 +08:00 |
|
Rasmus Wriedt Larsen
|
70489b2fc2
|
Merge branch 'main' into jorgectf/python/ldapinsecureauth
|
2021-09-23 10:05:56 +02:00 |
|
haby0
|
6c07a3e260
|
Apply @yoff's suggestion
|
2021-09-22 18:50:58 +08:00 |
|
haby0
|
99167539fb
|
Modify sinks
|
2021-09-17 17:29:40 +08:00 |
|
haby0
|
0277601705
|
Eliminate false positives caused by .
|
2021-09-16 20:59:34 +08:00 |
|
haby0
|
c60eded2de
|
Fix conflicting
|
2021-09-15 11:07:43 +08:00 |
|
haby0
|
9e63aa9d84
|
Update query
|
2021-09-14 21:12:49 +08:00 |
|
Rasmus Lerchedahl Petersen
|
36e27f2aa4
|
Python: Remove promoted code:
- queries (`py/regex-injection`)
- concepts (RegexExecution, RegexEscape)
- library models (Stdlib::Re)
|
2021-09-14 13:14:16 +02:00 |
|
jorgectf
|
2ccc6dc092
|
Merge branch 'main' into jorgectf/python/ldapinsecureauth
|
2021-09-14 09:32:19 +02:00 |
|
jorgectf
|
353c0a9ee7
|
Add missing comment
|
2021-09-12 20:44:04 +02:00 |
|
jorgectf
|
18b05bc56e
|
Fix tests and add global option
|
2021-09-12 20:35:57 +02:00 |
|
jorgectf
|
54012eba23
|
Optimize getFullHostRegex
|
2021-09-12 20:13:08 +02:00 |
|
jorgectf
|
61a81b60e8
|
Extend .qlref
|
2021-09-09 19:06:58 +02:00 |
|
jorgectf
|
21da603d81
|
Update .qlref
|
2021-09-07 20:13:39 +02:00 |
|
jorgectf
|
eee9b3f39e
|
Merge remote-tracking branch 'origin/main' into jorgectf/python/headerInjection
|
2021-09-07 19:54:58 +02:00 |
|
jorgectf
|
352eab0eca
|
Fix HeaderDeclaration class' comment
|
2021-09-07 19:44:25 +02:00 |
|