Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1164

Опубликовано: 21 янв. 2015
Источник: debian

Описание

Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-serve-staticfixed1.6.4-2package

Примечания

  • libv8 is not covered by security support

  • https://nodesecurity.io/advisories/serve-static-open-redirect

  • https://github.com/expressjs/serve-static/issues/26

Связанные уязвимости

ubuntu
около 11 лет назад

Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

nvd
около 11 лет назад

Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

CVSS3: 3.1
github
больше 5 лет назад

Open Redirect in serve-static