Описание
Stored Cross-Site Scripting in simplehttpserver
Simplehttpserver prior to version 0.1.0 are vulnerable to stored cross-site scripting (XSS). To be exploited an attacker needs to control the filename of a file that is used in the directory listing output. This version is patched in 0.1.0
Пакеты
Наименование
simplehttpserver
npm
Затронутые версииВерсия исправления
< 0.1.0
0.1.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 7 лет назад
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.