Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
211 |
test/core/resolveCache.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
435 |
lib/core/Manager.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
5 |
lib/core/resolvers/UrlResolver.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
76 |
lib/core/resolvers/GitRemoteResolver.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
113 |
lib/core/resolvers/SvnResolver.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
6 |
lib/commands/version.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
lib/util/download.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
106 |
lib/util/download.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
5 |
packages/bower-json/test/test.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
packages/bower-registry-client/lib/list.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
packages/bower-registry-client/lib/register.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
2 |
packages/bower-registry-client/lib/unregister.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
packages/bower-registry-client/lib/lookup.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
4 |
packages/bower-registry-client/lib/search.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
4 |
packages/bower-registry-client/lib/util/md5.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
8 |
packages/bower-config/lib/util/paths.js |