#select | domparser.js:10:55:10:57 | src | domparser.js:2:13:2:36 | documen ... .search | domparser.js:10:55:10:57 | src | XML parsing depends on a $@ without guarding against external entity expansion. | domparser.js:2:13:2:36 | documen ... .search | user-provided value | | domparser.js:12:57:12:59 | src | domparser.js:2:13:2:36 | documen ... .search | domparser.js:12:57:12:59 | src | XML parsing depends on a $@ without guarding against external entity expansion. | domparser.js:2:13:2:36 | documen ... .search | user-provided value | | libxml.noent.js:5:21:5:41 | req.par ... e-xml") | libxml.noent.js:5:21:5:41 | req.par ... e-xml") | libxml.noent.js:5:21:5:41 | req.par ... e-xml") | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.noent.js:5:21:5:41 | req.par ... e-xml") | user-provided value | | libxml.noent.js:9:21:9:41 | req.par ... e-xml") | libxml.noent.js:9:21:9:41 | req.par ... e-xml") | libxml.noent.js:9:21:9:41 | req.par ... e-xml") | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.noent.js:9:21:9:41 | req.par ... e-xml") | user-provided value | | libxml.noent.js:11:27:11:47 | req.par ... e-xml") | libxml.noent.js:11:27:11:47 | req.par ... e-xml") | libxml.noent.js:11:27:11:47 | req.par ... e-xml") | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.noent.js:11:27:11:47 | req.par ... e-xml") | user-provided value | | libxml.noent.js:12:27:12:66 | req.fil ... 'utf8') | libxml.noent.js:12:27:12:35 | req.files | libxml.noent.js:12:27:12:66 | req.fil ... 'utf8') | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.noent.js:12:27:12:35 | req.files | user-provided value | | libxml.sax.js:6:22:6:42 | req.par ... e-xml") | libxml.sax.js:6:22:6:42 | req.par ... e-xml") | libxml.sax.js:6:22:6:42 | req.par ... e-xml") | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.sax.js:6:22:6:42 | req.par ... e-xml") | user-provided value | | libxml.saxpush.js:6:15:6:35 | req.par ... e-xml") | libxml.saxpush.js:6:15:6:35 | req.par ... e-xml") | libxml.saxpush.js:6:15:6:35 | req.par ... e-xml") | XML parsing depends on a $@ without guarding against external entity expansion. | libxml.saxpush.js:6:15:6:35 | req.par ... e-xml") | user-provided value | edges | domparser.js:2:7:2:36 | src | domparser.js:10:55:10:57 | src | provenance | | | domparser.js:2:7:2:36 | src | domparser.js:12:57:12:59 | src | provenance | | | domparser.js:2:13:2:36 | documen ... .search | domparser.js:2:7:2:36 | src | provenance | | | libxml.noent.js:12:27:12:35 | req.files | libxml.noent.js:12:27:12:66 | req.fil ... 'utf8') | provenance | | nodes | domparser.js:2:7:2:36 | src | semmle.label | src | | domparser.js:2:13:2:36 | documen ... .search | semmle.label | documen ... .search | | domparser.js:10:55:10:57 | src | semmle.label | src | | domparser.js:12:57:12:59 | src | semmle.label | src | | libxml.noent.js:5:21:5:41 | req.par ... e-xml") | semmle.label | req.par ... e-xml") | | libxml.noent.js:9:21:9:41 | req.par ... e-xml") | semmle.label | req.par ... e-xml") | | libxml.noent.js:11:27:11:47 | req.par ... e-xml") | semmle.label | req.par ... e-xml") | | libxml.noent.js:12:27:12:35 | req.files | semmle.label | req.files | | libxml.noent.js:12:27:12:66 | req.fil ... 'utf8') | semmle.label | req.fil ... 'utf8') | | libxml.sax.js:6:22:6:42 | req.par ... e-xml") | semmle.label | req.par ... e-xml") | | libxml.saxpush.js:6:15:6:35 | req.par ... e-xml") | semmle.label | req.par ... e-xml") | subpaths