Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Marked | Marked_project | * | 0.3.2 (including) |
Node-marked | Ubuntu | artful | * |
Node-marked | Ubuntu | esm-apps/xenial | * |
Node-marked | Ubuntu | trusty | * |
Node-marked | Ubuntu | upstream | * |
Node-marked | Ubuntu | utopic | * |
Node-marked | Ubuntu | vivid | * |
Node-marked | Ubuntu | wily | * |
Node-marked | Ubuntu | xenial | * |
Node-marked | Ubuntu | yakkety | * |
Node-marked | Ubuntu | zesty | * |