Логотип exploitDog
bind:CVE-2018-6806
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-6806

Количество 2

Количество 2

nvd логотип

CVE-2018-6806

около 8 лет назад

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f8gc-r5jf-vqfm

больше 3 лет назад

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6806

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

CVSS3: 6.5
1%
Низкий
около 8 лет назад
github логотип
GHSA-f8gc-r5jf-vqfm

Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу