PT-2014-7827 · Unknown · Syntax-Error
Published
2014-12-11
·
Updated
2017-10-24
·
CVE-2014-7192
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
syntax-error versions prior to 1.1.1
Description
The issue allows remote attackers to execute arbitrary code via a crafted file, potentially leading to a cross-site scripting vulnerability. This may enable a malicious file to execute code when browserified.
Recommendations
For versions prior to 1.1.1, update to version 1.1.1 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Syntax-Error