[
{
"source_name": [
"$tempPath"
],
"source_line": [
18
],
"source_column": [
344
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php"
],
"sink_name": "move_uploaded_file",
"sink_line": 37,
"sink_column": 938,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php",
"vuln_name": "path_traversal",
"vuln_cwe": "CWE_22",
"vuln_id": "df13fe357b862d42ffb3ba7f9c6a36dee30cb7c5e99945c4f6c1c353807652e8",
"vuln_type": "taint-style"
},
{
"source_name": [
"$dstPath"
],
"source_line": [
36
],
"source_column": [
876
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php"
],
"sink_name": "move_uploaded_file",
"sink_line": 37,
"sink_column": 938,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php",
"vuln_name": "path_traversal",
"vuln_cwe": "CWE_22",
"vuln_id": "3b60be3d2938d00e2e9292d8391b13771b05670d0a768a6b0ff360583291de4e",
"vuln_type": "taint-style"
},
{
"source_name": [
"$name"
],
"source_line": [
19
],
"source_column": [
379
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php"
],
"sink_name": "echo",
"sink_line": 39,
"sink_column": 1008,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/upgrade_firmware.php",
"vuln_name": "xss",
"vuln_cwe": "CWE_79",
"vuln_id": "af83e2ca076e89a948c69240339ca647cdbf458cb7ff9e75e24f7b52b6e52817",
"vuln_type": "taint-style"
},
{
"source_name": [
"$url"
],
"source_line": [
115
],
"source_column": [
2887
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php"
],
"sink_name": "exit",
"sink_line": 116,
"sink_column": 2932,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php",
"vuln_name": "xss",
"vuln_cwe": "CWE_79",
"vuln_id": "4dbaff45ce32a29a7092257db747b9b26145c0eeb0ad3354560aefbacbd541ab",
"vuln_type": "taint-style"
},
{
"source_name": [
"$url"
],
"source_line": [
112
],
"source_column": [
2820
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php"
],
"sink_name": "header",
"sink_line": 120,
"sink_column": 2998,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php",
"vuln_name": "header_injection",
"vuln_cwe": "CWE_601",
"vuln_id": "ce009be80d77d281e26395d95f7621387156dceb668527089aab4e4e4142167a",
"vuln_type": "taint-style"
},
{
"source_name": [
"$url"
],
"source_line": [
115
],
"source_column": [
2887
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php"
],
"sink_name": "exit",
"sink_line": 116,
"sink_column": 2932,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php",
"vuln_name": "xss",
"vuln_cwe": "CWE_79",
"vuln_id": "523983a37e63401ad7c62c9fa8015e0c735f6825a4990768bff9734e8dad1d8a",
"vuln_type": "taint-style"
},
{
"source_name": [
"$url"
],
"source_line": [
112
],
"source_column": [
2820
],
"source_file": [
"\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php"
],
"sink_name": "header",
"sink_line": 120,
"sink_column": 2998,
"sink_file": "\/logs\/firmware\/unblob_extracted\/firmware_extract\/1568982-13971496.squashfs_v4_le_extract\/www\/public\/sdcard\/cpt\/app\/base_controller.php",
"vuln_name": "header_injection",
"vuln_cwe": "CWE_601",
"vuln_id": "801a06bd1f1955d6626be71a970ce6f413ebfc69cf9b765f963b873fe74801ca",
"vuln_type": "taint-style"
}
]