Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-6393

Опубликовано: 09 авг. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

released

4.16.4-1
disco

released

4.16.4-1
eoan

released

4.16.4-1
esm-apps/bionic

needed

esm-apps/focal

released

4.16.4-1
esm-apps/jammy

released

4.16.4-1
esm-apps/noble

released

4.16.4-1

Показывать по

Ссылки на источники

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

redhat
больше 10 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
nvd
около 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
debian
около 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ...

CVSS3: 6.1
github
около 7 лет назад

No Charset in Content-Type Header in express

4.3 Medium

CVSS2

6.1 Medium

CVSS3