Key Hardcoded |
A hardcoded key in plain text was identified. |
627 |
request.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
756 |
request.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
773 |
request.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
562 |
tests/test-oauth.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
34 |
tests/test-redirect-complex.js |
Key Hardcoded |
A hardcoded key in plain text was identified. |
64 |
tests/test-redirect-complex.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
78 |
tests/server.js |
Password Hardcoded |
A hardcoded password in plain text was identified. Store it properly in a config file. |
19 |
tests/test-tunnel.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
159 |
tests/test-pipes.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
177 |
tests/test-pipes.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
207 |
tests/test-pipes.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
347 |
tests/test-pipes.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
18 |
tests/test-timing.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
21 |
tests/test-timeout.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
41 |
tests/test-gzip.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
202 |
tests/test-gzip.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
226 |
tests/test-gzip.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
24 |
tests/test-form-data-error.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
17 |
tests/test-digest-auth.js |
Username Hardcoded |
A hardcoded username in plain text was identified. Store it properly in a config file. |
27 |
tests/test-digest-auth.js |
Username Hardcoded |
A hardcoded username in plain text was identified. Store it properly in a config file. |
75 |
tests/test-digest-auth.js |
Username Hardcoded |
A hardcoded username in plain text was identified. Store it properly in a config file. |
102 |
tests/test-digest-auth.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
69 |
lib/oauth.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
38 |
lib/helpers.js |