Количество 5
Количество 5

CVE-2014-6393
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVE-2014-6393
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVE-2014-6393
The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.
CVE-2014-6393
The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ...
GHSA-gpvr-g6gh-9mc2
No Charset in Content-Type Header in express
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2014-6393 The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. | CVSS3: 6.1 | 0% Низкий | почти 8 лет назад |
![]() | CVE-2014-6393 The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. | CVSS2: 4.3 | 0% Низкий | больше 10 лет назад |
![]() | CVE-2014-6393 The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. | CVSS3: 6.1 | 0% Низкий | почти 8 лет назад |
CVE-2014-6393 The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ... | CVSS3: 6.1 | 0% Низкий | почти 8 лет назад | |
GHSA-gpvr-g6gh-9mc2 No Charset in Content-Type Header in express | CVSS3: 6.1 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу