The JS-YAML module before 2.0.5 for... CVE-2013-4660

6.8 AV AC AU C I A
发布: 2013-06-28
修订: 2013-07-01

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.

0%
当前有2条漏洞利用/PoC
当前有20条受影响产品信息