mirror of
https://github.com/github/codeql.git
synced 2026-03-26 17:28:29 +01:00
28 lines
2.4 KiB
Plaintext
28 lines
2.4 KiB
Plaintext
nodes
|
|
| AdmZipBad.js:6:24:6:41 | zipEntry.entryName |
|
|
| TarSlipBad.js:6:36:6:46 | header.name |
|
|
| ZipSlipBad2.js:5:9:5:46 | fileName |
|
|
| ZipSlipBad2.js:5:20:5:46 | 'output ... ry.path |
|
|
| ZipSlipBad2.js:5:37:5:46 | entry.path |
|
|
| ZipSlipBad2.js:6:22:6:29 | fileName |
|
|
| ZipSlipBad.js:7:11:7:31 | fileName |
|
|
| ZipSlipBad.js:7:22:7:31 | entry.path |
|
|
| ZipSlipBad.js:8:37:8:44 | fileName |
|
|
| ZipSlipBadUnzipper.js:7:9:7:29 | fileName |
|
|
| ZipSlipBadUnzipper.js:7:20:7:29 | entry.path |
|
|
| ZipSlipBadUnzipper.js:8:37:8:44 | fileName |
|
|
edges
|
|
| ZipSlipBad2.js:5:9:5:46 | fileName | ZipSlipBad2.js:6:22:6:29 | fileName |
|
|
| ZipSlipBad2.js:5:20:5:46 | 'output ... ry.path | ZipSlipBad2.js:5:9:5:46 | fileName |
|
|
| ZipSlipBad2.js:5:37:5:46 | entry.path | ZipSlipBad2.js:5:20:5:46 | 'output ... ry.path |
|
|
| ZipSlipBad.js:7:11:7:31 | fileName | ZipSlipBad.js:8:37:8:44 | fileName |
|
|
| ZipSlipBad.js:7:22:7:31 | entry.path | ZipSlipBad.js:7:11:7:31 | fileName |
|
|
| ZipSlipBadUnzipper.js:7:9:7:29 | fileName | ZipSlipBadUnzipper.js:8:37:8:44 | fileName |
|
|
| ZipSlipBadUnzipper.js:7:20:7:29 | entry.path | ZipSlipBadUnzipper.js:7:9:7:29 | fileName |
|
|
#select
|
|
| AdmZipBad.js:6:24:6:41 | zipEntry.entryName | AdmZipBad.js:6:24:6:41 | zipEntry.entryName | AdmZipBad.js:6:24:6:41 | zipEntry.entryName | Unsanitized zip archive $@, which may contain '..', is used in a file system operation. | AdmZipBad.js:6:24:6:41 | zipEntry.entryName | item path |
|
|
| TarSlipBad.js:6:36:6:46 | header.name | TarSlipBad.js:6:36:6:46 | header.name | TarSlipBad.js:6:36:6:46 | header.name | Unsanitized zip archive $@, which may contain '..', is used in a file system operation. | TarSlipBad.js:6:36:6:46 | header.name | item path |
|
|
| ZipSlipBad2.js:6:22:6:29 | fileName | ZipSlipBad2.js:5:37:5:46 | entry.path | ZipSlipBad2.js:6:22:6:29 | fileName | Unsanitized zip archive $@, which may contain '..', is used in a file system operation. | ZipSlipBad2.js:5:37:5:46 | entry.path | item path |
|
|
| ZipSlipBad.js:8:37:8:44 | fileName | ZipSlipBad.js:7:22:7:31 | entry.path | ZipSlipBad.js:8:37:8:44 | fileName | Unsanitized zip archive $@, which may contain '..', is used in a file system operation. | ZipSlipBad.js:7:22:7:31 | entry.path | item path |
|
|
| ZipSlipBadUnzipper.js:8:37:8:44 | fileName | ZipSlipBadUnzipper.js:7:20:7:29 | entry.path | ZipSlipBadUnzipper.js:8:37:8:44 | fileName | Unsanitized zip archive $@, which may contain '..', is used in a file system operation. | ZipSlipBadUnzipper.js:7:20:7:29 | entry.path | item path |
|