Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
anywhere allows embedding HTML in file names, which in certain conditions allows execution of malicious JavaScript.