Key Hardcoded |
A hardcoded key in plain text was identified. |
177 |
client/fontello/system/event_actions/event_actions.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
178 |
client/fontello/system/event_actions/event_actions.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
179 |
client/fontello/system/event_actions/event_actions.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
180 |
client/fontello/system/event_actions/event_actions.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
43 |
client/fontello/system/io_progress/io_progress.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
284 |
client/fontello/system/navigate/navigate.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
58 |
client/fontello/system/notify/notify.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
96 |
client/fontello/system/notify/notify.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
132 |
client/fontello/system/notify/notify.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
397 |
client/fontello/app/import/import.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
10 |
client/fontello/app/session/session.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
16 |
client/fontello/layout/layout.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
28 |
internal/fontello/font_build/font_build.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
125 |
internal/fontello/font_build/_lib/worker.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
44 |
lib/system/worker_pool.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
73 |
lib/system/worker_pool.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
82 |
lib/system/worker_pool.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
4 |
lib/system/init/server.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
651 |
lib/system/runner/initialize.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
344 |
lib/autoload/hooks/init/service_http.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
414 |
lib/autoload/hooks/init/service_http.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
117 |
lib/bundler/index.js |
Server Side Injection(SSI) - eval() |
User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
30 |
lib/bundler/plugins/macros.js |
Server Side Injection(SSI) - new Function() |
User controlled data in 'new Function()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
32 |
lib/bundler/plugins/macros.js |