Описание
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-marked | fixed | 0.3.6+dfsg-1 | package |
Примечания
https://nodesecurity.io/advisories/marked_vbscript_injection
https://github.com/chjj/marked/issues/492
libv8 is not covered by security support
Связанные уязвимости
ubuntu
около 11 лет назад
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
nvd
около 11 лет назад
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.