Loading...
Loading...
Compare original and translation side by side
composer require --dev vimeo/psalm./vendor/bin/psalm --init./vendor/bin/psalm --versioncomposer require --dev vimeo/psalm./vendor/bin/psalm --init./vendor/bin/psalm --version./vendor/bin/psalm --taint-analysis --output-format=json > psalm-results.json./vendor/bin/psalm --taint-analysis src/ --output-format=json./vendor/bin/psalm --taint-analysis --level=1 --output-format=json./vendor/bin/psalm --taint-analysis --show-info=true --output-format=json| # | Severity | Type | File:Line | Finding | Taint Flow | Remediation |
|---|----------|------|-----------|---------|------------|-------------|./vendor/bin/psalm --taint-analysis --output-format=json > psalm-results.json./vendor/bin/psalm --taint-analysis src/ --output-format=json./vendor/bin/psalm --taint-analysis --level=1 --output-format=json./vendor/bin/psalm --taint-analysis --show-info=true --output-format=json| 序号 | 严重程度 | 类型 | 文件:行号 | 检测结果 | 污点流 | 修复建议 |
|---|----------|------|-----------|---------|------------|-------------|| Taint Type | Risk |
|---|---|
| TaintedSql | SQL injection via unsanitized input |
| TaintedHtml | XSS via unescaped output |
| TaintedShell | Command injection |
| TaintedFile | Path traversal |
| TaintedHeader | HTTP header injection |
| TaintedSSRF | Server-side request forgery |
| TaintedUnserialize | Insecure deserialization |
| TaintedInclude | Remote/local file inclusion |
| TaintedEval | Code injection via eval |
| TaintedLdap | LDAP injection |
| 污点类型 | 风险 |
|---|---|
| TaintedSql | 未过滤输入导致SQL注入 |
| TaintedHtml | 未转义输出导致XSS |
| TaintedShell | 命令注入 |
| TaintedFile | 路径遍历 |
| TaintedHeader | HTTP头注入 |
| TaintedSSRF | 服务器端请求伪造(SSRF) |
| TaintedUnserialize | 不安全的反序列化 |
| TaintedInclude | 远程/本地文件包含 |
| TaintedEval | 通过eval进行代码注入 |
| TaintedLdap | LDAP注入 |