|
42 | 42 | | xss-through-dom.js:154:25:154:27 | msg | xss-through-dom.js:155:27:155:29 | msg | provenance | | |
43 | 43 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | xss-through-dom.js:154:25:154:27 | msg | provenance | | |
44 | 44 | nodes |
45 | | -| angular.ts:11:24:11:41 | event.target.value | semmle.label | event.target.value | |
46 | | -| angular.ts:15:24:15:35 | target.value | semmle.label | target.value | |
| 45 | +| angular.ts:12:24:12:41 | event.target.value | semmle.label | event.target.value | |
| 46 | +| angular.ts:16:24:16:35 | target.value | semmle.label | target.value | |
47 | 47 | | forms.js:8:23:8:28 | values | semmle.label | values | |
48 | 48 | | forms.js:9:31:9:36 | values | semmle.label | values | |
49 | 49 | | forms.js:9:31:9:40 | values.foo | semmle.label | values.foo | |
@@ -126,8 +126,8 @@ nodes |
126 | 126 | | xss-through-dom.js:159:34:159:52 | $("textarea").val() | semmle.label | $("textarea").val() | |
127 | 127 | subpaths |
128 | 128 | #select |
129 | | -| angular.ts:11:24:11:41 | event.target.value | angular.ts:11:24:11:41 | event.target.value | angular.ts:11:24:11:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:11:24:11:41 | event.target.value | DOM text | |
130 | | -| angular.ts:15:24:15:35 | target.value | angular.ts:15:24:15:35 | target.value | angular.ts:15:24:15:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:15:24:15:35 | target.value | DOM text | |
| 129 | +| angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | angular.ts:12:24:12:41 | event.target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:12:24:12:41 | event.target.value | DOM text | |
| 130 | +| angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | angular.ts:16:24:16:35 | target.value | $@ is reinterpreted as HTML without escaping meta-characters. | angular.ts:16:24:16:35 | target.value | DOM text | |
131 | 131 | | forms.js:9:31:9:40 | values.foo | forms.js:8:23:8:28 | values | forms.js:9:31:9:40 | values.foo | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:8:23:8:28 | values | DOM text | |
132 | 132 | | forms.js:12:31:12:40 | values.bar | forms.js:11:24:11:29 | values | forms.js:12:31:12:40 | values.bar | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:11:24:11:29 | values | DOM text | |
133 | 133 | | forms.js:25:23:25:34 | values.email | forms.js:24:15:24:20 | values | forms.js:25:23:25:34 | values.email | $@ is reinterpreted as HTML without escaping meta-characters. | forms.js:24:15:24:20 | values | DOM text | |
|
0 commit comments