Module LDAPInjectionQuery
Provides a taint-tracking configuration for reasoning about unvalidated user input that is used to construct LDAP queries.
Import path
import semmle.code.csharp.security.dataflow.LDAPInjectionQuery
Imports
csharp |
The default C# QL library. |
Classes
DirectoryEntryPathSink |
An argument that sets the |
DirectorySearcherFilterSink |
A argument that sets the |
LdapEncodeSanitizer |
A call to a method which is named “LDAP*Encode”, which is likely to be an LDAP sanitizer. |
RemoteSource |
A source of remote user input. |
Sanitizer |
A sanitizer for unvalidated user input that is used to construct LDAP queries. |
SearchRequestFilterSink |
A argument that sets the |
Sink |
A data flow sink for unvalidated user input that is used to construct LDAP queries. |
Source |
A data flow source for unvalidated user input that is used to construct LDAP queries. |
TaintTrackingConfiguration |
DEPRECATED: Use |
Modules
LdapInjectionConfig |
A taint-tracking configuration for unvalidated user input that is used to construct LDAP queries. |
Aliases
LDAPEncodeSanitizer |
DEPRECATED: Alias for LdapEncodeSanitizer |
LdapInjection |
A taint-tracking configuration for unvalidated user input that is used to construct LDAP queries. |