[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-10531 -- node-marked

ID: oval:org.secpod.oval:def:1901180Date: (C)2019-03-04   (M)2023-12-20
Class: VULNERABILITYFamily: unix




marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it"s possible to bypass marked"s content injection protection to inject a `javascript:` URL. This flaw exists because `&#xNNanything;` gets parsed to what it could and leaves the rest behind, resulting in just `anything;` being left.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
node-marked
Reference:
CVE-2016-10531
CVE    1
CVE-2016-10531
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:node-marked:node-marked
cpe:/o:ubuntu:ubuntu_linux:14.04

© SecPod Technologies