CodeQL library for Ruby
codeql/ruby-all 0.8.15-dev (changelog, source)
Search

Module ActionView

Modeling for ActionView.

Import path

import codeql.ruby.frameworks.ActionView

Classes

ArgumentInterpretedAsUrl

An argument to a method call which constructs a script tag, interpreting the argument as a URL. Remote input flowing to this argument may allow loading of arbitrary javascript.

Modules

Helpers

Action view helper methods which are XSS sinks.