Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-10549

Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin header. This would allow an attacker to make AJAX requests to vulnerable hosts through cross site scripting or a malicious HTML Document, effectively bypassing the Same Origin Policy. Note that this is only an issue when `allRoutes` is set to `true` and `origin` is set to `*` or left commented out in the sails CORS config file. The problem can be compounded when the cors `credentials` setting is not provided. At that point authenticated cross domain requests are possible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.7%
CVSS Severity
CVSS v3 Score 4.4
CVSS v2 Score 2.1
Products affected by CVE-2016-10549
  • Sailsjs » Sails » Version: N/A
    cpe:2.3:a:sailsjs:sails:-
  • Sailsjs » Sails » Version: 0.0.0
    cpe:2.3:a:sailsjs:sails:0.0.0
  • Sailsjs » Sails » Version: 0.0.0-1
    cpe:2.3:a:sailsjs:sails:0.0.0-1
  • Sailsjs » Sails » Version: 0.0.0-2
    cpe:2.3:a:sailsjs:sails:0.0.0-2
  • Sailsjs » Sails » Version: 0.1.5
    cpe:2.3:a:sailsjs:sails:0.1.5
  • Sailsjs » Sails » Version: 0.1.5-1
    cpe:2.3:a:sailsjs:sails:0.1.5-1
  • Sailsjs » Sails » Version: 0.1.6-0
    cpe:2.3:a:sailsjs:sails:0.1.6-0
  • Sailsjs » Sails » Version: 0.10.0
    cpe:2.3:a:sailsjs:sails:0.10.0
  • Sailsjs » Sails » Version: 0.10.00
    cpe:2.3:a:sailsjs:sails:0.10.00
  • Sailsjs » Sails » Version: 0.10.01
    cpe:2.3:a:sailsjs:sails:0.10.01
  • Sailsjs » Sails » Version: 0.10.1
    cpe:2.3:a:sailsjs:sails:0.10.1
  • Sailsjs » Sails » Version: 0.10.2
    cpe:2.3:a:sailsjs:sails:0.10.2
  • Sailsjs » Sails » Version: 0.10.3
    cpe:2.3:a:sailsjs:sails:0.10.3
  • Sailsjs » Sails » Version: 0.10.4
    cpe:2.3:a:sailsjs:sails:0.10.4
  • Sailsjs » Sails » Version: 0.10.5
    cpe:2.3:a:sailsjs:sails:0.10.5
  • Sailsjs » Sails » Version: 0.11.0
    cpe:2.3:a:sailsjs:sails:0.11.0
  • Sailsjs » Sails » Version: 0.11.1
    cpe:2.3:a:sailsjs:sails:0.11.1
  • Sailsjs » Sails » Version: 0.11.2
    cpe:2.3:a:sailsjs:sails:0.11.2
  • Sailsjs » Sails » Version: 0.11.3
    cpe:2.3:a:sailsjs:sails:0.11.3
  • Sailsjs » Sails » Version: 0.11.4
    cpe:2.3:a:sailsjs:sails:0.11.4
  • Sailsjs » Sails » Version: 0.11.5
    cpe:2.3:a:sailsjs:sails:0.11.5
  • Sailsjs » Sails » Version: 0.11.6-0
    cpe:2.3:a:sailsjs:sails:0.11.6-0
  • Sailsjs » Sails » Version: 0.11.6-1
    cpe:2.3:a:sailsjs:sails:0.11.6-1
  • Sailsjs » Sails » Version: 0.11.7-0
    cpe:2.3:a:sailsjs:sails:0.11.7-0
  • Sailsjs » Sails » Version: 0.12.0
    cpe:2.3:a:sailsjs:sails:0.12.0
  • Sailsjs » Sails » Version: 0.12.07
    cpe:2.3:a:sailsjs:sails:0.12.07
  • Sailsjs » Sails » Version: 0.12.1
    cpe:2.3:a:sailsjs:sails:0.12.1
  • Sailsjs » Sails » Version: 0.12.2
    cpe:2.3:a:sailsjs:sails:0.12.2
  • Sailsjs » Sails » Version: 0.12.2-0
    cpe:2.3:a:sailsjs:sails:0.12.2-0
  • Sailsjs » Sails » Version: 0.12.3
    cpe:2.3:a:sailsjs:sails:0.12.3
  • Sailsjs » Sails » Version: 0.12.4
    cpe:2.3:a:sailsjs:sails:0.12.4
  • Sailsjs » Sails » Version: 0.12.5
    cpe:2.3:a:sailsjs:sails:0.12.5
  • Sailsjs » Sails » Version: 0.12.6
    cpe:2.3:a:sailsjs:sails:0.12.6
  • Sailsjs » Sails » Version: 0.12.7
    cpe:2.3:a:sailsjs:sails:0.12.7
  • Sailsjs » Sails » Version: 0.2.0
    cpe:2.3:a:sailsjs:sails:0.2.0
  • Sailsjs » Sails » Version: 0.2.1
    cpe:2.3:a:sailsjs:sails:0.2.1
  • Sailsjs » Sails » Version: 0.3.0
    cpe:2.3:a:sailsjs:sails:0.3.0
  • Sailsjs » Sails » Version: 0.4.0
    cpe:2.3:a:sailsjs:sails:0.4.0
  • Sailsjs » Sails » Version: 0.4.1
    cpe:2.3:a:sailsjs:sails:0.4.1
  • Sailsjs » Sails » Version: 0.4.2
    cpe:2.3:a:sailsjs:sails:0.4.2
  • Sailsjs » Sails » Version: 0.4.3
    cpe:2.3:a:sailsjs:sails:0.4.3
  • Sailsjs » Sails » Version: 0.4.4
    cpe:2.3:a:sailsjs:sails:0.4.4
  • Sailsjs » Sails » Version: 0.4.5
    cpe:2.3:a:sailsjs:sails:0.4.5
  • Sailsjs » Sails » Version: 0.4.6
    cpe:2.3:a:sailsjs:sails:0.4.6
  • Sailsjs » Sails » Version: 0.4.7
    cpe:2.3:a:sailsjs:sails:0.4.7
  • Sailsjs » Sails » Version: 0.5.0
    cpe:2.3:a:sailsjs:sails:0.5.0
  • Sailsjs » Sails » Version: 0.5.1
    cpe:2.3:a:sailsjs:sails:0.5.1
  • Sailsjs » Sails » Version: 0.5.2
    cpe:2.3:a:sailsjs:sails:0.5.2
  • Sailsjs » Sails » Version: 0.6.0
    cpe:2.3:a:sailsjs:sails:0.6.0
  • Sailsjs » Sails » Version: 0.6.1
    cpe:2.3:a:sailsjs:sails:0.6.1
  • Sailsjs » Sails » Version: 0.7.0
    cpe:2.3:a:sailsjs:sails:0.7.0
  • Sailsjs » Sails » Version: 0.7.0-1
    cpe:2.3:a:sailsjs:sails:0.7.0-1
  • Sailsjs » Sails » Version: 0.7.0-2
    cpe:2.3:a:sailsjs:sails:0.7.0-2
  • Sailsjs » Sails » Version: 0.7.0-3
    cpe:2.3:a:sailsjs:sails:0.7.0-3
  • Sailsjs » Sails » Version: 0.7.0-4
    cpe:2.3:a:sailsjs:sails:0.7.0-4
  • Sailsjs » Sails » Version: 0.7.0-5
    cpe:2.3:a:sailsjs:sails:0.7.0-5
  • Sailsjs » Sails » Version: 0.7.0-6
    cpe:2.3:a:sailsjs:sails:0.7.0-6
  • Sailsjs » Sails » Version: 0.7.0-7
    cpe:2.3:a:sailsjs:sails:0.7.0-7
  • Sailsjs » Sails » Version: 0.7.0-8
    cpe:2.3:a:sailsjs:sails:0.7.0-8
  • Sailsjs » Sails » Version: 0.7.1
    cpe:2.3:a:sailsjs:sails:0.7.1
  • Sailsjs » Sails » Version: 0.7.1-0
    cpe:2.3:a:sailsjs:sails:0.7.1-0
  • Sailsjs » Sails » Version: 0.7.2
    cpe:2.3:a:sailsjs:sails:0.7.2
  • Sailsjs » Sails » Version: 0.7.3
    cpe:2.3:a:sailsjs:sails:0.7.3
  • Sailsjs » Sails » Version: 0.7.4
    cpe:2.3:a:sailsjs:sails:0.7.4
  • Sailsjs » Sails » Version: 0.7.4-1
    cpe:2.3:a:sailsjs:sails:0.7.4-1
  • Sailsjs » Sails » Version: 0.7.5-0
    cpe:2.3:a:sailsjs:sails:0.7.5-0
  • Sailsjs » Sails » Version: 0.7.6-0
    cpe:2.3:a:sailsjs:sails:0.7.6-0
  • Sailsjs » Sails » Version: 0.7.7
    cpe:2.3:a:sailsjs:sails:0.7.7
  • Sailsjs » Sails » Version: 0.7.7-0
    cpe:2.3:a:sailsjs:sails:0.7.7-0
  • Sailsjs » Sails » Version: 0.7.8
    cpe:2.3:a:sailsjs:sails:0.7.8
  • Sailsjs » Sails » Version: 0.7.9
    cpe:2.3:a:sailsjs:sails:0.7.9
  • Sailsjs » Sails » Version: 0.8.0
    cpe:2.3:a:sailsjs:sails:0.8.0
  • Sailsjs » Sails » Version: 0.8.1
    cpe:2.3:a:sailsjs:sails:0.8.1
  • Sailsjs » Sails » Version: 0.8.2
    cpe:2.3:a:sailsjs:sails:0.8.2
  • Sailsjs » Sails » Version: 0.8.3
    cpe:2.3:a:sailsjs:sails:0.8.3
  • Sailsjs » Sails » Version: 0.8.4
    cpe:2.3:a:sailsjs:sails:0.8.4
  • Sailsjs » Sails » Version: 0.8.5
    cpe:2.3:a:sailsjs:sails:0.8.5
  • Sailsjs » Sails » Version: 0.8.6
    cpe:2.3:a:sailsjs:sails:0.8.6
  • Sailsjs » Sails » Version: 0.8.7
    cpe:2.3:a:sailsjs:sails:0.8.7
  • Sailsjs » Sails » Version: 0.8.71
    cpe:2.3:a:sailsjs:sails:0.8.71
  • Sailsjs » Sails » Version: 0.8.72
    cpe:2.3:a:sailsjs:sails:0.8.72
  • Sailsjs » Sails » Version: 0.8.73
    cpe:2.3:a:sailsjs:sails:0.8.73
  • Sailsjs » Sails » Version: 0.8.74
    cpe:2.3:a:sailsjs:sails:0.8.74
  • Sailsjs » Sails » Version: 0.8.75
    cpe:2.3:a:sailsjs:sails:0.8.75
  • Sailsjs » Sails » Version: 0.8.76
    cpe:2.3:a:sailsjs:sails:0.8.76
  • Sailsjs » Sails » Version: 0.8.77
    cpe:2.3:a:sailsjs:sails:0.8.77
  • Sailsjs » Sails » Version: 0.8.78
    cpe:2.3:a:sailsjs:sails:0.8.78
  • Sailsjs » Sails » Version: 0.8.79
    cpe:2.3:a:sailsjs:sails:0.8.79
  • Sailsjs » Sails » Version: 0.8.80
    cpe:2.3:a:sailsjs:sails:0.8.80
  • Sailsjs » Sails » Version: 0.8.81
    cpe:2.3:a:sailsjs:sails:0.8.81
  • Sailsjs » Sails » Version: 0.8.82
    cpe:2.3:a:sailsjs:sails:0.8.82
  • Sailsjs » Sails » Version: 0.8.83
    cpe:2.3:a:sailsjs:sails:0.8.83
  • Sailsjs » Sails » Version: 0.8.84
    cpe:2.3:a:sailsjs:sails:0.8.84
  • Sailsjs » Sails » Version: 0.8.85
    cpe:2.3:a:sailsjs:sails:0.8.85
  • Sailsjs » Sails » Version: 0.8.86
    cpe:2.3:a:sailsjs:sails:0.8.86
  • Sailsjs » Sails » Version: 0.8.87
    cpe:2.3:a:sailsjs:sails:0.8.87
  • Sailsjs » Sails » Version: 0.8.88
    cpe:2.3:a:sailsjs:sails:0.8.88
  • Sailsjs » Sails » Version: 0.8.89
    cpe:2.3:a:sailsjs:sails:0.8.89
  • Sailsjs » Sails » Version: 0.8.89-1
    cpe:2.3:a:sailsjs:sails:0.8.89-1
  • Sailsjs » Sails » Version: 0.8.892
    cpe:2.3:a:sailsjs:sails:0.8.892
  • Sailsjs » Sails » Version: 0.8.894
    cpe:2.3:a:sailsjs:sails:0.8.894
  • Sailsjs » Sails » Version: 0.8.895
    cpe:2.3:a:sailsjs:sails:0.8.895
  • Sailsjs » Sails » Version: 0.8.9
    cpe:2.3:a:sailsjs:sails:0.8.9
  • Sailsjs » Sails » Version: 0.8.91
    cpe:2.3:a:sailsjs:sails:0.8.91
  • Sailsjs » Sails » Version: 0.8.92
    cpe:2.3:a:sailsjs:sails:0.8.92
  • Sailsjs » Sails » Version: 0.8.93
    cpe:2.3:a:sailsjs:sails:0.8.93
  • Sailsjs » Sails » Version: 0.8.94
    cpe:2.3:a:sailsjs:sails:0.8.94
  • Sailsjs » Sails » Version: 0.9.0
    cpe:2.3:a:sailsjs:sails:0.9.0
  • Sailsjs » Sails » Version: 0.9.1
    cpe:2.3:a:sailsjs:sails:0.9.1
  • Sailsjs » Sails » Version: 0.9.10
    cpe:2.3:a:sailsjs:sails:0.9.10
  • Sailsjs » Sails » Version: 0.9.11
    cpe:2.3:a:sailsjs:sails:0.9.11
  • Sailsjs » Sails » Version: 0.9.12
    cpe:2.3:a:sailsjs:sails:0.9.12
  • Sailsjs » Sails » Version: 0.9.13
    cpe:2.3:a:sailsjs:sails:0.9.13
  • Sailsjs » Sails » Version: 0.9.15
    cpe:2.3:a:sailsjs:sails:0.9.15
  • Sailsjs » Sails » Version: 0.9.16
    cpe:2.3:a:sailsjs:sails:0.9.16
  • Sailsjs » Sails » Version: 0.9.17
    cpe:2.3:a:sailsjs:sails:0.9.17
  • Sailsjs » Sails » Version: 0.9.2
    cpe:2.3:a:sailsjs:sails:0.9.2
  • Sailsjs » Sails » Version: 0.9.3
    cpe:2.3:a:sailsjs:sails:0.9.3
  • Sailsjs » Sails » Version: 0.9.4
    cpe:2.3:a:sailsjs:sails:0.9.4
  • Sailsjs » Sails » Version: 0.9.5
    cpe:2.3:a:sailsjs:sails:0.9.5
  • Sailsjs » Sails » Version: 0.9.6
    cpe:2.3:a:sailsjs:sails:0.9.6
  • Sailsjs » Sails » Version: 0.9.7
    cpe:2.3:a:sailsjs:sails:0.9.7
  • Sailsjs » Sails » Version: 0.9.8
    cpe:2.3:a:sailsjs:sails:0.9.8
  • Sailsjs » Sails » Version: 0.9.9
    cpe:2.3:a:sailsjs:sails:0.9.9


Contact Us

Shodan ® - All rights reserved