Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-6393

Опубликовано: 09 авг. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

released

4.16.4-1
disco

released

4.16.4-1
eoan

released

4.16.4-1
esm-apps/bionic

needed

esm-apps/focal

released

4.16.4-1
esm-apps/jammy

released

4.16.4-1
esm-apps/noble

released

4.16.4-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 52%
0.0029
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
nvd
почти 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
debian
почти 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ...

CVSS3: 6.1
github
больше 6 лет назад

No Charset in Content-Type Header in express

EPSS

Процентиль: 52%
0.0029
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3