Server Side Injection(SSI) - eval() |
User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
17 |
test/functional/addtag.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
42 |
test/functional/nullstorage.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
8 |
test/functional/scoped.js |
Remote OS Command Execution |
User controlled data in 'child_process.exec()' can result in Remote OS Command Execution. |
7 |
test/functional/index.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
45 |
test/functional/gh29.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
42 |
test/functional/incomplete.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
36 |
test/functional/racycrash.js |
Server Side Injection(SSI) - eval() |
User controlled data in eval() can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
17 |
test/functional/gzip.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
8 |
test/functional/newnpmreg.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
52 |
test/functional/basic.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
62 |
test/functional/basic.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
115 |
test/functional/lib/server.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
test/functional/lib/smart_request.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
test/unit/toplevel.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
7 |
test/unit/mystreams.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
38 |
lib/auth.js |
Weak Hash used - MD5 |
MD5 is a a weak hash which is known to have collision. Use a strong hashing function. |
76 |
lib/middleware.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
175 |
lib/local-fs.js |
Weak Hash used - SHA1 |
SHA1 is a a weak hash which is known to have collision. Use a strong hashing function. |
352 |
lib/local-storage.js |
SSRF - Server Side Request Forgery |
User controlled data in 'request()'' can result in Server Side Request Forgery (SSRF). |
3 |
lib/up-storage.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
317 |
lib/static/main.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
335 |
lib/static/main.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
2 |
lib/static/jquery.min.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
4 |
lib/static/jquery.min.js |
Server Side Injection(SSI) - setInterval() |
User controlled data in 'setInterval()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
4 |
lib/static/jquery.min.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
16 |
lib/GUI/js/entry.js |
Server Side Injection(SSI) - setTimeout() |
User controlled data in 'setTimeout()' can result in Server Side Injection (SSI) or Remote Code Execution (RCE). |
34 |
lib/GUI/js/entry.js |