[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-10531 -- node-marked

ID: oval:org.secpod.oval:def:1901180Date: (C)2019-03-04   (M)2023-12-20
Class: VULNERABILITYFamily: unix




marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML entities, it"s possible to bypass marked"s content injection protection to inject a `javascript:` URL. This flaw exists because `&#xNNanything;` gets parsed to what it could and leaves the rest behind, resulting in just `anything;` being left.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
node-marked
Reference:
CVE-2016-10531
CVE    1
CVE-2016-10531
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:node-marked:node-marked
cpe:/o:ubuntu:ubuntu_linux:14.04

© SecPod Technologies