Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-1370

Опубликовано: 27 янв. 2015
Источник: debian

Описание

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-markedfixed0.3.6+dfsg-1package

Примечания

  • https://nodesecurity.io/advisories/marked_vbscript_injection

  • https://github.com/chjj/marked/issues/492

  • libv8 is not covered by security support

Связанные уязвимости

ubuntu
около 11 лет назад

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

nvd
около 11 лет назад

Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

github
больше 8 лет назад

VBScript Content Injection in marked