Compare commits

...

1 Commits

Author SHA1 Message Date
Esben Sparre Andreasen
b935a7f4d7 remove the even-lined results from two ATM queries 2022-06-24 09:31:00 +02:00
2 changed files with 4 additions and 2 deletions

View File

@@ -25,7 +25,8 @@ from DataFlow::Configuration cfg, DataFlow::PathNode source, DataFlow::PathNode
where
cfg.hasFlowPath(source, sink) and
not isFlowLikelyInBaseQuery(source.getNode(), sink.getNode()) and
score = getScoreForFlow(source.getNode(), sink.getNode())
score = getScoreForFlow(source.getNode(), sink.getNode()) and
sink.getNode().getStartLine() % 2 = 0
select sink.getNode(), source, sink,
"(Experimental) This may be a path that depends on $@. Identified using machine learning.",
source.getNode(), "a user-provided value", score

View File

@@ -22,7 +22,8 @@ from DataFlow::Configuration cfg, DataFlow::PathNode source, DataFlow::PathNode
where
cfg.hasFlowPath(source, sink) and
not isFlowLikelyInBaseQuery(source.getNode(), sink.getNode()) and
score = getScoreForFlow(source.getNode(), sink.getNode())
score = getScoreForFlow(source.getNode(), sink.getNode()) and
sink.getNode().getStartLine() % 2 = 0
select sink.getNode(), source, sink,
"(Experimental) This may be a cross-site scripting vulnerability due to $@. Identified using machine learning.",
source.getNode(), "a user-provided value", score