Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Joyent Node.js marked 不完整黑名单漏洞
Vulnerability Description
Joyent Node.js是美国Joyent公司的一套建立在Google V8 JavaScript引擎之上的网络应用平台。marked是其中的一个Markdown(一种轻量级标记语言)解析器和编译器。 Joyent Node.js marked 0.3.2及之前版本中存在不完整黑名单漏洞。远程攻击者可借助链接里的‘vbscript’标签利用该漏洞实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A