Vulnerabilities > CVE-2015-1370 - Unspecified vulnerability in Marked Project Marked
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Vulnerable Configurations
References
- http://www.openwall.com/lists/oss-security/2015/01/23/2
- http://www.openwall.com/lists/oss-security/2015/01/23/2
- https://github.com/chjj/marked/issues/492
- https://github.com/chjj/marked/issues/492
- https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1ba
- https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1ba
- https://nodesecurity.io/advisories/marked_vbscript_injection
- https://nodesecurity.io/advisories/marked_vbscript_injection