|
2 | 2 | | XXE.java:22:43:22:66 | getInputStream(...) : ServletInputStream | XXE.java:24:18:24:35 | servletInputStream | |
3 | 3 | | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | XXE.java:32:17:32:18 | br : BufferedReader | |
4 | 4 | | XXE.java:32:17:32:18 | br : BufferedReader | XXE.java:32:17:32:29 | readLine(...) : String | |
5 | | -| XXE.java:32:17:32:29 | readLine(...) : String | XXE.java:35:48:35:68 | toString(...) | |
| 5 | +| XXE.java:32:17:32:29 | readLine(...) : String | XXE.java:33:22:33:24 | str : String | |
| 6 | +| XXE.java:33:4:33:13 | listString [post update] : StringBuilder | XXE.java:35:48:35:57 | listString : StringBuilder | |
| 7 | +| XXE.java:33:22:33:24 | str : String | XXE.java:33:4:33:13 | listString [post update] : StringBuilder | |
| 8 | +| XXE.java:35:48:35:57 | listString : StringBuilder | XXE.java:35:48:35:68 | toString(...) | |
6 | 9 | | XXE.java:40:43:40:66 | getInputStream(...) : ServletInputStream | XXE.java:44:42:44:59 | servletInputStream : ServletInputStream | |
7 | 10 | | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource | XXE.java:45:22:45:27 | source | |
8 | 11 | | XXE.java:44:42:44:59 | servletInputStream : ServletInputStream | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource | |
|
15 | 18 | | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | semmle.label | getReader(...) : BufferedReader | |
16 | 19 | | XXE.java:32:17:32:18 | br : BufferedReader | semmle.label | br : BufferedReader | |
17 | 20 | | XXE.java:32:17:32:29 | readLine(...) : String | semmle.label | readLine(...) : String | |
| 21 | +| XXE.java:33:4:33:13 | listString [post update] : StringBuilder | semmle.label | listString [post update] : StringBuilder | |
| 22 | +| XXE.java:33:22:33:24 | str : String | semmle.label | str : String | |
| 23 | +| XXE.java:35:48:35:57 | listString : StringBuilder | semmle.label | listString : StringBuilder | |
18 | 24 | | XXE.java:35:48:35:68 | toString(...) | semmle.label | toString(...) | |
19 | 25 | | XXE.java:40:43:40:66 | getInputStream(...) : ServletInputStream | semmle.label | getInputStream(...) : ServletInputStream | |
20 | 26 | | XXE.java:44:25:44:60 | new StreamSource(...) : StreamSource | semmle.label | new StreamSource(...) : StreamSource | |
|
25 | 31 | | XXE.java:51:42:51:59 | servletInputStream : ServletInputStream | semmle.label | servletInputStream : ServletInputStream | |
26 | 32 | | XXE.java:52:3:52:12 | xmlDecoder | semmle.label | xmlDecoder | |
27 | 33 | | XXE.java:57:49:57:72 | getInputStream(...) | semmle.label | getInputStream(...) | |
| 34 | +subpaths |
28 | 35 | #select |
29 | 36 | | XXE.java:24:18:24:35 | servletInputStream | XXE.java:22:43:22:66 | getInputStream(...) : ServletInputStream | XXE.java:24:18:24:35 | servletInputStream | Unsafe parsing of XML file from $@. | XXE.java:22:43:22:66 | getInputStream(...) | user input | |
30 | 37 | | XXE.java:35:48:35:68 | toString(...) | XXE.java:29:23:29:41 | getReader(...) : BufferedReader | XXE.java:35:48:35:68 | toString(...) | Unsafe parsing of XML file from $@. | XXE.java:29:23:29:41 | getReader(...) | user input | |
|
0 commit comments