CodeQL library for JavaScript/TypeScript
codeql/javascript-all 2.6.5 (changelog, source)
Search

Module SecondOrderCommandInjectionQuery

Provides a taint tracking configuration for reasoning about second order command-injection vulnerabilities.

Note, for performance reasons: only import this file if SecondOrderCommandInjection::Configuration is needed, otherwise SecondOrderCommandInjectionCustomizations should be imported instead.

Import path

import semmle.javascript.security.dataflow.SecondOrderCommandInjectionQuery

Imports

SecondOrderCommandInjection

Classes and predicates for reasoning about second order command injection.

javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Classes

Configuration

DEPRECATED. Use the SecondOrderCommandInjectionFlow module instead.

Modules

SecondOrderCommandInjectionConfig

A taint-tracking configuration for reasoning about second order command-injection vulnerabilities.

Aliases

SecondOrderCommandInjectionFlow

Taint-tracking for reasoning about second order command-injection vulnerabilities.