edges | NoSQLCodeInjection.js:18:24:18:31 | req.body | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | provenance | | | NoSQLCodeInjection.js:19:36:19:43 | req.body | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | provenance | | | NoSQLCodeInjection.js:22:36:22:43 | req.body | NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | provenance | | | eslint-escope-build.js:20:22:20:22 | c | eslint-escope-build.js:21:16:21:16 | c | provenance | | | express.js:6:44:6:62 | req.param("wobble") | express.js:6:24:6:69 | "return ... + "];" | provenance | | | express.js:7:54:7:72 | req.param("wobble") | express.js:7:34:7:79 | "return ... + "];" | provenance | | | express.js:9:28:9:46 | req.param("wobble") | express.js:9:8:9:53 | "return ... + "];" | provenance | | | express.js:19:9:19:35 | taint | express.js:20:34:20:38 | taint | provenance | | | express.js:19:17:19:35 | req.param("wobble") | express.js:19:9:19:35 | taint | provenance | | | express.js:27:9:27:35 | taint | express.js:36:15:36:19 | taint | provenance | | | express.js:27:17:27:35 | req.param("wobble") | express.js:27:9:27:35 | taint | provenance | | | express.js:42:30:42:32 | msg | express.js:43:10:43:12 | msg | provenance | | | react-native.js:7:7:7:33 | tainted | react-native.js:8:32:8:38 | tainted | provenance | | | react-native.js:7:7:7:33 | tainted | react-native.js:10:23:10:29 | tainted | provenance | | | react-native.js:7:17:7:33 | req.param("code") | react-native.js:7:7:7:33 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:20:17:20:23 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:21:16:21:22 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:22:18:22:24 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:23:17:23:23 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:24:18:24:24 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:25:16:25:22 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:26:27:26:33 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:27:21:27:27 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:28:17:28:23 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:29:24:29:30 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:30:21:30:27 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:31:19:31:25 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:32:16:32:22 | tainted | provenance | | | template-sinks.js:18:9:18:31 | tainted | template-sinks.js:33:17:33:23 | tainted | provenance | | | template-sinks.js:18:19:18:31 | req.query.foo | template-sinks.js:18:9:18:31 | tainted | provenance | | | tst.js:1:6:1:27 | documen ... on.href | tst.js:1:6:1:83 | documen ... t=")+8) | provenance | | | tst.js:11:10:11:33 | documen ... .search | tst.js:11:10:11:74 | documen ... , "$1") | provenance | | | tst.js:17:11:17:32 | documen ... on.hash | tst.js:17:11:17:45 | documen ... ring(1) | provenance | | | tst.js:17:11:17:45 | documen ... ring(1) | tst.js:17:6:17:46 | atob(do ... ing(1)) | provenance | | | tst.js:19:26:19:40 | location.search | tst.js:19:26:19:53 | locatio ... ring(1) | provenance | | | tst.js:22:9:22:82 | source | tst.js:24:18:24:23 | source | provenance | | | tst.js:22:9:22:82 | source | tst.js:26:14:26:19 | source | provenance | | | tst.js:22:9:22:82 | source | tst.js:28:28:28:33 | source | provenance | | | tst.js:22:9:22:82 | source | tst.js:30:33:30:38 | source | provenance | | | tst.js:22:18:22:41 | documen ... .search | tst.js:22:18:22:82 | documen ... , "$1") | provenance | | | tst.js:22:18:22:82 | documen ... , "$1") | tst.js:22:9:22:82 | source | provenance | | nodes | NoSQLCodeInjection.js:18:24:18:31 | req.body | semmle.label | req.body | | NoSQLCodeInjection.js:18:24:18:37 | req.body.query | semmle.label | req.body.query | | NoSQLCodeInjection.js:19:24:19:48 | "name = ... dy.name | semmle.label | "name = ... dy.name | | NoSQLCodeInjection.js:19:36:19:43 | req.body | semmle.label | req.body | | NoSQLCodeInjection.js:22:24:22:48 | "name = ... dy.name | semmle.label | "name = ... dy.name | | NoSQLCodeInjection.js:22:36:22:43 | req.body | semmle.label | req.body | | actions.js:4:10:4:50 | github. ... message | semmle.label | github. ... message | | angularjs.js:10:22:10:36 | location.search | semmle.label | location.search | | angularjs.js:13:23:13:37 | location.search | semmle.label | location.search | | angularjs.js:16:28:16:42 | location.search | semmle.label | location.search | | angularjs.js:19:22:19:36 | location.search | semmle.label | location.search | | angularjs.js:22:27:22:41 | location.search | semmle.label | location.search | | angularjs.js:25:23:25:37 | location.search | semmle.label | location.search | | angularjs.js:28:33:28:47 | location.search | semmle.label | location.search | | angularjs.js:31:28:31:42 | location.search | semmle.label | location.search | | angularjs.js:34:18:34:32 | location.search | semmle.label | location.search | | angularjs.js:40:18:40:32 | location.search | semmle.label | location.search | | angularjs.js:44:17:44:31 | location.search | semmle.label | location.search | | angularjs.js:47:16:47:30 | location.search | semmle.label | location.search | | angularjs.js:50:22:50:36 | location.search | semmle.label | location.search | | angularjs.js:53:32:53:46 | location.search | semmle.label | location.search | | eslint-escope-build.js:20:22:20:22 | c | semmle.label | c | | eslint-escope-build.js:21:16:21:16 | c | semmle.label | c | | express.js:6:24:6:69 | "return ... + "];" | semmle.label | "return ... + "];" | | express.js:6:44:6:62 | req.param("wobble") | semmle.label | req.param("wobble") | | express.js:7:34:7:79 | "return ... + "];" | semmle.label | "return ... + "];" | | express.js:7:54:7:72 | req.param("wobble") | semmle.label | req.param("wobble") | | express.js:9:8:9:53 | "return ... + "];" | semmle.label | "return ... + "];" | | express.js:9:28:9:46 | req.param("wobble") | semmle.label | req.param("wobble") | | express.js:11:22:11:54 | req.par ... ction") | semmle.label | req.par ... ction") | | express.js:12:30:12:53 | req.par ... cript") | semmle.label | req.par ... cript") | | express.js:13:37:13:70 | req.par ... odule") | semmle.label | req.par ... odule") | | express.js:14:19:14:48 | req.par ... ntext") | semmle.label | req.par ... ntext") | | express.js:19:9:19:35 | taint | semmle.label | taint | | express.js:19:17:19:35 | req.param("wobble") | semmle.label | req.param("wobble") | | express.js:20:34:20:38 | taint | semmle.label | taint | | express.js:27:9:27:35 | taint | semmle.label | taint | | express.js:27:17:27:35 | req.param("wobble") | semmle.label | req.param("wobble") | | express.js:36:15:36:19 | taint | semmle.label | taint | | express.js:42:30:42:32 | msg | semmle.label | msg | | express.js:43:10:43:12 | msg | semmle.label | msg | | module.js:9:16:9:29 | req.query.code | semmle.label | req.query.code | | module.js:11:17:11:30 | req.query.code | semmle.label | req.query.code | | react-native.js:7:7:7:33 | tainted | semmle.label | tainted | | react-native.js:7:17:7:33 | req.param("code") | semmle.label | req.param("code") | | react-native.js:8:32:8:38 | tainted | semmle.label | tainted | | react-native.js:10:23:10:29 | tainted | semmle.label | tainted | | react.js:10:56:10:77 | documen ... on.hash | semmle.label | documen ... on.hash | | template-sinks.js:18:9:18:31 | tainted | semmle.label | tainted | | template-sinks.js:18:19:18:31 | req.query.foo | semmle.label | req.query.foo | | template-sinks.js:20:17:20:23 | tainted | semmle.label | tainted | | template-sinks.js:21:16:21:22 | tainted | semmle.label | tainted | | template-sinks.js:22:18:22:24 | tainted | semmle.label | tainted | | template-sinks.js:23:17:23:23 | tainted | semmle.label | tainted | | template-sinks.js:24:18:24:24 | tainted | semmle.label | tainted | | template-sinks.js:25:16:25:22 | tainted | semmle.label | tainted | | template-sinks.js:26:27:26:33 | tainted | semmle.label | tainted | | template-sinks.js:27:21:27:27 | tainted | semmle.label | tainted | | template-sinks.js:28:17:28:23 | tainted | semmle.label | tainted | | template-sinks.js:29:24:29:30 | tainted | semmle.label | tainted | | template-sinks.js:30:21:30:27 | tainted | semmle.label | tainted | | template-sinks.js:31:19:31:25 | tainted | semmle.label | tainted | | template-sinks.js:32:16:32:22 | tainted | semmle.label | tainted | | template-sinks.js:33:17:33:23 | tainted | semmle.label | tainted | | tst.js:1:6:1:27 | documen ... on.href | semmle.label | documen ... on.href | | tst.js:1:6:1:83 | documen ... t=")+8) | semmle.label | documen ... t=")+8) | | tst.js:3:12:3:33 | documen ... on.hash | semmle.label | documen ... on.hash | | tst.js:11:10:11:33 | documen ... .search | semmle.label | documen ... .search | | tst.js:11:10:11:74 | documen ... , "$1") | semmle.label | documen ... , "$1") | | tst.js:13:21:13:42 | documen ... on.hash | semmle.label | documen ... on.hash | | tst.js:15:30:15:51 | documen ... on.hash | semmle.label | documen ... on.hash | | tst.js:17:6:17:46 | atob(do ... ing(1)) | semmle.label | atob(do ... ing(1)) | | tst.js:17:11:17:32 | documen ... on.hash | semmle.label | documen ... on.hash | | tst.js:17:11:17:45 | documen ... ring(1) | semmle.label | documen ... ring(1) | | tst.js:19:26:19:40 | location.search | semmle.label | location.search | | tst.js:19:26:19:53 | locatio ... ring(1) | semmle.label | locatio ... ring(1) | | tst.js:22:9:22:82 | source | semmle.label | source | | tst.js:22:18:22:41 | documen ... .search | semmle.label | documen ... .search | | tst.js:22:18:22:82 | documen ... , "$1") | semmle.label | documen ... , "$1") | | tst.js:24:18:24:23 | source | semmle.label | source | | tst.js:26:14:26:19 | source | semmle.label | source | | tst.js:28:28:28:33 | source | semmle.label | source | | tst.js:30:33:30:38 | source | semmle.label | source | | webix/webix.html:3:16:3:37 | documen ... on.hash | semmle.label | documen ... on.hash | | webix/webix.html:4:26:4:47 | documen ... on.hash | semmle.label | documen ... on.hash | | webix/webix.html:5:47:5:68 | documen ... on.hash | semmle.label | documen ... on.hash | | webix/webix.js:3:12:3:33 | documen ... on.hash | semmle.label | documen ... on.hash | | webix/webix.js:4:22:4:43 | documen ... on.hash | semmle.label | documen ... on.hash | | webix/webix.js:5:43:5:64 | documen ... on.hash | semmle.label | documen ... on.hash | subpaths #select | eslint-escope-build.js:21:16:21:16 | c | eslint-escope-build.js:20:22:20:22 | c | eslint-escope-build.js:21:16:21:16 | c | $@ flows to here and is interpreted as code. | eslint-escope-build.js:20:22:20:22 | c | User-provided value |