PT-2014-7827 · Unknown · Syntax-Error

Published

2014-12-11

·

Updated

2017-10-24

·

CVE-2014-7192

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions syntax-error versions prior to 1.1.1
Description The issue allows remote attackers to execute arbitrary code via a crafted file, potentially leading to a cross-site scripting vulnerability. This may enable a malicious file to execute code when browserified.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7192
GHSA-5726-G6R9-5F22

Affected Products

Syntax-Error