VYPR

Windows Seleniumjar Node Module

by Hackerone

CVEs (3)

  • CVE-2016-10691HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an…

  • CVE-2016-10687HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested…

  • CVE-2016-10670HigJun 4, 2018
    risk 0.53cvss 8.1epss 0.02

    windows-seleniumjar-mirror downloads the Selenium Jar file windows-seleniumjar-mirror downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an…