基础信息
项目名称:chenxianming/quickcms
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1716644179991117824/1716644181673033728
此报告由Murphysec提供
漏洞列表
暂无
缺陷组件
暂无
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 146 | 低 |
Apache-2.0 | 7 | 低 |
ISC | 15 | 低 |
BSD-3-Clause | 12 | 低 |
BSD-2-Clause | 1 | 低 |
自定义许可证 | 1 | 低 |
Unlicense | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
http-errors | https://registry.npmjs.org/http-errors/-/http-errors-1.5.1.tgz | 直接依赖 | npm |
has-ansi | https://registry.npmjs.org/has-ansi/-/has-ansi-2.0.0.tgz | 直接依赖 | npm |
combined-stream | https://registry.npm.taobao.org/combined-stream/download/combined-stream-1.0.5.tgz | 直接依赖 | npm |
ejs | https://registry.npm.taobao.org/ejs/download/ejs-2.4.2.tgz | 直接依赖 | npm |
basic-auth | https://registry.npm.taobao.org/basic-auth/download/basic-auth-1.0.4.tgz | 直接依赖 | npm |
depd | https://registry.npmjs.org/depd/-/depd-1.1.0.tgz | 直接依赖 | npm |
jsbn | https://registry.npmjs.org/jsbn/-/jsbn-0.1.1.tgz | 直接依赖 | npm |
once | https://registry.npm.taobao.org/once/download/once-1.4.0.tgz | 直接依赖 | npm |
source-map-support | https://registry.npmjs.org/source-map-support/-/source-map-support-0.3.3.tgz | 直接依赖 | npm |
klaw | https://registry.npmjs.org/klaw/-/klaw-1.3.1.tgz | 直接依赖 | npm |
util-deprecate | https://registry.npmjs.org/util-deprecate/-/util-deprecate-1.0.2.tgz | 直接依赖 | npm |
readable-stream | https://registry.npmjs.org/readable-stream/-/readable-stream-1.1.14.tgz | 直接依赖 | npm |
destroy | https://registry.npmjs.org/destroy/-/destroy-1.0.4.tgz | 直接依赖 | npm |
iconv-lite | https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.4.13.tgz | 直接依赖 | npm |
process-nextick-args | https://registry.npm.taobao.org/process-nextick-args/download/process-nextick-args-1.0.7.tgz | 直接依赖 | npm |
mime-types | https://registry.npmjs.org/mime-types/-/mime-types-2.1.13.tgz | 直接依赖 | npm |
vary | https://registry.npmjs.org/vary/-/vary-1.0.1.tgz | 直接依赖 | npm |
escape-string-regexp | https://registry.npmjs.org/escape-string-regexp/-/escape-string-regexp-1.0.5.tgz | 直接依赖 | npm |
uid-safe | https://registry.npmjs.org/uid-safe/-/uid-safe-2.1.3.tgz | 直接依赖 | npm |
chalk | https://registry.npmjs.org/chalk/-/chalk-1.1.3.tgz | 直接依赖 | npm |
aws-sign2 | https://registry.npm.taobao.org/aws-sign2/download/aws-sign2-0.6.0.tgz | 直接依赖 | npm |
aws4 | https://registry.npmjs.org/aws4/-/aws4-1.6.0.tgz | 直接依赖 | npm |
charenc | https://registry.npmjs.org/charenc/-/charenc-0.0.2.tgz | 直接依赖 | npm |
isstream | https://registry.npmjs.org/isstream/-/isstream-0.1.2.tgz | 直接依赖 | npm |
balanced-match | https://registry.npm.taobao.org/balanced-match/download/balanced-match-0.4.2.tgz | 直接依赖 | npm |
express-useragent | https://registry.npmjs.org/express-useragent/-/express-useragent-1.0.7.tgz | 直接依赖 | npm |
parseurl | https://registry.npmjs.org/parseurl/-/parseurl-1.3.1.tgz | 直接依赖 | npm |
cookie-signature | https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.0.6.tgz | 直接依赖 | npm |
archiver | https://registry.npmjs.org/archiver/-/archiver-1.3.0.tgz | 直接依赖 | npm |
connect-multiparty | https://registry.npm.taobao.org/connect-multiparty/download/connect-multiparty-2.0.0.tgz | 直接依赖 | npm |
lazystream | https://registry.npmjs.org/lazystream/-/lazystream-1.0.0.tgz | 直接依赖 | npm |
commander | https://registry.npmjs.org/commander/-/commander-2.9.0.tgz | 直接依赖 | npm |
is-md5 | https://registry.npm.taobao.org/is-md5/download/is-md5-0.0.2.tgz | 直接依赖 | npm |
amdefine | https://registry.npmjs.org/amdefine/-/amdefine-1.0.1.tgz | 直接依赖 | npm |
bcrypt-pbkdf | https://registry.npmjs.org/bcrypt-pbkdf/-/bcrypt-pbkdf-1.0.1.tgz | 直接依赖 | npm |
mkdirp | https://registry.npmjs.org/mkdirp/-/mkdirp-0.5.1.tgz | 直接依赖 | npm |
sntp | https://registry.npm.taobao.org/sntp/download/sntp-1.0.9.tgz | 直接依赖 | npm |
on-headers | https://registry.npmjs.org/on-headers/-/on-headers-1.0.1.tgz | 直接依赖 | npm |
generate-function | https://registry.npm.taobao.org/generate-function/download/generate-function-2.0.0.tgz | 直接依赖 | npm |
etag | https://registry.npmjs.org/etag/-/etag-1.7.0.tgz | 直接依赖 | npm |
statuses | https://registry.npmjs.org/statuses/-/statuses-1.3.1.tgz | 直接依赖 | npm |
typedarray | https://registry.npmjs.org/typedarray/-/typedarray-0.0.6.tgz | 直接依赖 | npm |
tough-cookie | https://registry.npm.taobao.org/tough-cookie/download/tough-cookie-2.3.2.tgz | 直接依赖 | npm |
supports-color | https://registry.npmjs.org/supports-color/-/supports-color-2.0.0.tgz | 直接依赖 | npm |
concat-map | https://registry.npmjs.org/concat-map/-/concat-map-0.0.1.tgz | 直接依赖 | npm |
brace-expansion | https://registry.npm.taobao.org/brace-expansion/download/brace-expansion-1.1.6.tgz | 直接依赖 | npm |
walkdir | https://registry.npmjs.org/walkdir/-/walkdir-0.0.11.tgz | 直接依赖 | npm |
morgan | https://registry.npm.taobao.org/morgan/download/morgan-1.7.0.tgz | 直接依赖 | npm |
hoek | https://registry.npmjs.org/hoek/-/hoek-2.16.3.tgz | 直接依赖 | npm |
xtend | https://registry.npmjs.org/xtend/-/xtend-4.0.1.tgz | 直接依赖 | npm |
utils-merge | https://registry.npmjs.org/utils-merge/-/utils-merge-1.0.0.tgz | 直接依赖 | npm |
delayed-stream | https://registry.npm.taobao.org/delayed-stream/download/delayed-stream-1.0.0.tgz | 直接依赖 | npm |
string_decoder | https://registry.npmjs.org/string_decoder/-/string_decoder-0.10.31.tgz | 直接依赖 | npm |
zip-stream | https://registry.npmjs.org/zip-stream/-/zip-stream-1.1.1.tgz | 直接依赖 | npm |
har-validator | https://registry.npm.taobao.org/har-validator/download/har-validator-2.0.6.tgz | 直接依赖 | npm |
jsonfile | https://registry.npm.taobao.org/jsonfile/download/jsonfile-2.4.0.tgz | 直接依赖 | npm |
ee-first | https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz | 直接依赖 | npm |
array-flatten | https://registry.npm.taobao.org/array-flatten/download/array-flatten-1.1.1.tgz | 直接依赖 | npm |
crc | https://registry.npm.taobao.org/crc/download/crc-3.4.0.tgz | 直接依赖 | npm |
finalhandler | https://registry.npm.taobao.org/finalhandler/download/finalhandler-0.4.1.tgz | 直接依赖 | npm |
block-stream | https://registry.npm.taobao.org/block-stream/download/block-stream-0.0.9.tgz | 直接依赖 | npm |
cryptiles | https://registry.npm.taobao.org/cryptiles/download/cryptiles-2.0.5.tgz | 直接依赖 | npm |
bl | https://registry.npmjs.org/bl/-/bl-1.2.0.tgz | 直接依赖 | npm |
http-signature | https://registry.npm.taobao.org/http-signature/download/http-signature-1.1.1.tgz | 直接依赖 | npm |
accepts | https://registry.npmjs.org/accepts/-/accepts-1.2.13.tgz | 直接依赖 | npm |
multiparty | https://registry.npmjs.org/multiparty/-/multiparty-4.1.3.tgz | 直接依赖 | npm |
forwarded | https://registry.npm.taobao.org/forwarded/download/forwarded-0.1.0.tgz | 直接依赖 | npm |
tough-cookie-filestore | https://registry.npmjs.org/tough-cookie-filestore/-/tough-cookie-filestore-0.0.1.tgz | 直接依赖 | npm |
extract-zip | https://registry.npmjs.org/extract-zip/-/extract-zip-1.6.0.tgz | 直接依赖 | npm |
express-session | https://registry.npmjs.org/express-session/-/express-session-1.15.1.tgz | 直接依赖 | npm |
raw-body | https://registry.npm.taobao.org/raw-body/download/raw-body-2.1.7.tgz | 直接依赖 | npm |
express-rate-limit | 2.9.0 | 直接依赖 | npm |
mime | https://registry.npmjs.org/mime/-/mime-1.3.4.tgz | 直接依赖 | npm |
path-is-absolute | https://registry.npm.taobao.org/path-is-absolute/download/path-is-absolute-1.0.1.tgz | 直接依赖 | npm |
escape-html | https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz | 直接依赖 | npm |
normalize-path | https://registry.npmjs.org/normalize-path/-/normalize-path-2.0.1.tgz | 直接依赖 | npm |
sshpk | https://registry.npmjs.org/sshpk/-/sshpk-1.10.2.tgz | 直接依赖 | npm |
extsprintf | https://registry.npm.taobao.org/extsprintf/download/extsprintf-1.0.2.tgz | 直接依赖 | npm |
fresh | https://registry.npmjs.org/fresh/-/fresh-0.3.0.tgz | 直接依赖 | npm |
body-parser | https://registry.npm.taobao.org/body-parser/download/body-parser-1.15.2.tgz | 直接依赖 | npm |
merge-descriptors | https://registry.npm.taobao.org/merge-descriptors/download/merge-descriptors-1.0.1.tgz | 直接依赖 | npm |
base64-url | https://registry.npmjs.org/base64-url/-/base64-url-1.3.3.tgz | 直接依赖 | npm |
is-typedarray | https://registry.npm.taobao.org/is-typedarray/download/is-typedarray-1.0.0.tgz | 直接依赖 | npm |
archiver-utils | https://registry.npmjs.org/archiver-utils/-/archiver-utils-1.3.0.tgz | 直接依赖 | npm |
sqlstring | https://registry.npmjs.org/sqlstring/-/sqlstring-2.2.0.tgz | 直接依赖 | npm |
md5 | https://registry.npm.taobao.org/md5/download/md5-2.2.1.tgz | 直接依赖 | npm |
inflight | https://registry.npmjs.org/inflight/-/inflight-1.0.6.tgz | 直接依赖 | npm |
lodash | https://registry.npmjs.org/lodash/-/lodash-3.10.1.tgz | 直接依赖 | npm |
json-schema | https://registry.npmjs.org/json-schema/-/json-schema-0.2.3.tgz | 直接依赖 | npm |
fs-extra | https://registry.npmjs.org/fs-extra/-/fs-extra-2.0.0.tgz | 直接依赖 | npm |
jodid25519 | https://registry.npm.taobao.org/jodid25519/download/jodid25519-1.0.2.tgz | 直接依赖 | npm |
asn1 | https://registry.npm.taobao.org/asn1/download/asn1-0.2.3.tgz | 直接依赖 | npm |
fd-slicer | https://registry.npmjs.org/fd-slicer/-/fd-slicer-1.0.1.tgz | 直接依赖 | npm |
tweetnacl | https://registry.npmjs.org/tweetnacl/-/tweetnacl-0.14.5.tgz | 直接依赖 | npm |
forever-agent | https://registry.npm.taobao.org/forever-agent/download/forever-agent-0.6.1.tgz | 直接依赖 | npm |
cookie-parser | https://registry.npm.taobao.org/cookie-parser/download/cookie-parser-1.4.3.tgz | 直接依赖 | npm |
is-my-json-valid | https://registry.npmjs.org/is-my-json-valid/-/is-my-json-valid-2.15.0.tgz | 直接依赖 | npm |
bignumber.js | https://registry.npmjs.org/bignumber.js/-/bignumber.js-2.4.0.tgz | 直接依赖 | npm |
send | https://registry.npmjs.org/send/-/send-0.13.1.tgz | 直接依赖 | npm |
ecc-jsbn | https://registry.npm.taobao.org/ecc-jsbn/download/ecc-jsbn-0.1.1.tgz | 直接依赖 | npm |
proxy-addr | https://registry.npm.taobao.org/proxy-addr/download/proxy-addr-1.0.10.tgz | 直接依赖 | npm |
base64-coder-node | https://registry.npm.taobao.org/base64-coder-node/download/base64-coder-node-1.0.7.tgz | 直接依赖 | npm |
content-type | https://registry.npm.taobao.org/content-type/download/content-type-1.0.2.tgz | 直接依赖 | npm |
object-encrypter | https://registry.npm.taobao.org/object-encrypter/download/object-encrypter-0.1.3.tgz | 直接依赖 | npm |
inherits | https://registry.npm.taobao.org/inherits/download/inherits-2.0.3.tgz | 直接依赖 | npm |
mq-node | https://registry.npmjs.org/mq-node/-/mq-node-1.0.11.tgz | 直接依赖 | npm |
mysql | https://registry.npmjs.org/mysql/-/mysql-2.12.0.tgz | 直接依赖 | npm |
qs | https://registry.npm.taobao.org/qs/download/qs-6.2.0.tgz | 直接依赖 | npm |
jsonpointer | https://registry.npmjs.org/jsonpointer/-/jsonpointer-4.0.1.tgz | 直接依赖 | npm |
parse-seconds | https://registry.npmjs.org/parse-seconds/-/parse-seconds-1.0.0.tgz | 直接依赖 | npm |
on-finished | https://registry.npmjs.org/on-finished/-/on-finished-2.3.0.tgz | 直接依赖 | npm |
json-stringify-safe | https://registry.npm.taobao.org/json-stringify-safe/download/json-stringify-safe-5.0.1.tgz | 直接依赖 | npm |
pend | https://registry.npmjs.org/pend/-/pend-1.2.0.tgz | 直接依赖 | npm |
express | https://registry.npm.taobao.org/express/download/express-4.13.4.tgz | 直接依赖 | npm |
negotiator | https://registry.npmjs.org/negotiator/-/negotiator-0.5.3.tgz | 直接依赖 | npm |
methods | https://registry.npmjs.org/methods/-/methods-1.1.2.tgz | 直接依赖 | npm |
cookie | https://registry.npm.taobao.org/cookie/download/cookie-0.3.1.tgz | 直接依赖 | npm |
ipaddr.js | https://registry.npm.taobao.org/ipaddr.js/download/ipaddr.js-1.0.5.tgz | 直接依赖 | npm |
express-mysql-session | https://registry.npmjs.org/express-mysql-session/-/express-mysql-session-1.2.0.tgz | 直接依赖 | npm |
debug | https://registry.npmjs.org/debug/-/debug-2.2.0.tgz | 直接依赖 | npm |
oauth-sign | https://registry.npm.taobao.org/oauth-sign/download/oauth-sign-0.8.2.tgz | 直接依赖 | npm |
hawk | https://registry.npm.taobao.org/hawk/download/hawk-3.1.3.tgz | 直接依赖 | npm |
rimraf | https://registry.npmjs.org/rimraf/-/rimraf-2.6.1.tgz | 直接依赖 | npm |
range-parser | https://registry.npmjs.org/range-parser/-/range-parser-1.0.3.tgz | 直接依赖 | npm |
asynckit | https://registry.npmjs.org/asynckit/-/asynckit-0.4.0.tgz | 直接依赖 | npm |
serve-favicon | https://registry.npmjs.org/serve-favicon/-/serve-favicon-2.3.2.tgz | 直接依赖 | npm |
form-data | https://registry.npmjs.org/form-data/-/form-data-2.1.2.tgz | 直接依赖 | npm |
bytes | https://registry.npm.taobao.org/bytes/download/bytes-2.4.0.tgz | 直接依赖 | npm |
source-map | https://registry.npmjs.org/source-map/-/source-map-0.1.32.tgz | 直接依赖 | npm |
is-buffer | https://registry.npm.taobao.org/is-buffer/download/is-buffer-1.1.4.tgz | 直接依赖 | npm |
graceful-fs | https://registry.npmjs.org/graceful-fs/-/graceful-fs-4.1.11.tgz | 直接依赖 | npm |
concat-stream | https://registry.npmjs.org/concat-stream/-/concat-stream-1.5.0.tgz | 直接依赖 | npm |
dashdash | https://registry.npmjs.org/dashdash/-/dashdash-1.14.1.tgz | 直接依赖 | npm |
content-disposition | https://registry.npm.taobao.org/content-disposition/download/content-disposition-0.5.1.tgz | 直接依赖 | npm |
is-property | https://registry.npm.taobao.org/is-property/download/is-property-1.0.2.tgz | 直接依赖 | npm |
minimatch | https://registry.npm.taobao.org/minimatch/download/minimatch-3.0.3.tgz | 直接依赖 | npm |
wrappy | https://registry.npm.taobao.org/wrappy/download/wrappy-1.0.2.tgz | 直接依赖 | npm |
getpass | https://registry.npm.taobao.org/getpass/download/getpass-0.1.6.tgz | 直接依赖 | npm |
punycode | https://registry.npm.taobao.org/punycode/download/punycode-1.4.1.tgz | 直接依赖 | npm |
crc32-stream | https://registry.npmjs.org/crc32-stream/-/crc32-stream-1.0.1.tgz | 直接依赖 | npm |
buffer-shims | https://registry.npm.taobao.org/buffer-shims/download/buffer-shims-1.0.0.tgz | 直接依赖 | npm |
end-of-stream | https://registry.npmjs.org/end-of-stream/-/end-of-stream-1.1.0.tgz | 直接依赖 | npm |
tunnel-agent | https://registry.npm.taobao.org/tunnel-agent/download/tunnel-agent-0.4.3.tgz | 直接依赖 | npm |
core-util-is | https://registry.npmjs.org/core-util-is/-/core-util-is-1.0.2.tgz | 直接依赖 | npm |
serve-static | https://registry.npm.taobao.org/serve-static/download/serve-static-1.10.3.tgz | 直接依赖 | npm |
compress-commons | https://registry.npmjs.org/compress-commons/-/compress-commons-1.1.0.tgz | 直接依赖 | npm |
type-is | https://registry.npmjs.org/type-is/-/type-is-1.6.14.tgz | 直接依赖 | npm |
ansi-regex | https://registry.npmjs.org/ansi-regex/-/ansi-regex-2.1.1.tgz | 直接依赖 | npm |
connect-flash | https://registry.npm.taobao.org/connect-flash/download/connect-flash-0.1.1.tgz | 直接依赖 | npm |
strip-ansi | https://registry.npmjs.org/strip-ansi/-/strip-ansi-3.0.1.tgz | 直接依赖 | npm |
buffer-crc32 | https://registry.npmjs.org/buffer-crc32/-/buffer-crc32-0.2.13.tgz | 直接依赖 | npm |
pinkie | https://registry.npmjs.org/pinkie/-/pinkie-2.0.4.tgz | 直接依赖 | npm |
caseless | https://registry.npm.taobao.org/caseless/download/caseless-0.11.0.tgz | 直接依赖 | npm |
graceful-readlink | https://registry.npmjs.org/graceful-readlink/-/graceful-readlink-1.0.1.tgz | 直接依赖 | npm |
tar | https://registry.npm.taobao.org/tar/download/tar-2.2.1.tgz | 直接依赖 | npm |
isarray | https://registry.npmjs.org/isarray/-/isarray-0.0.1.tgz | 直接依赖 | npm |
glob | https://registry.npmjs.org/glob/-/glob-7.1.1.tgz | 直接依赖 | npm |
fs.realpath | https://registry.npm.taobao.org/fs.realpath/download/fs.realpath-1.0.0.tgz | 直接依赖 | npm |
defaults | 1.0.3 | 直接依赖 | npm |
boom | https://registry.npm.taobao.org/boom/download/boom-2.10.1.tgz | 直接依赖 | npm |
my-wget | https://registry.npmjs.org/my-wget/-/my-wget-1.1.0.tgz | 直接依赖 | npm |
jsprim | https://registry.npmjs.org/jsprim/-/jsprim-1.3.1.tgz | 直接依赖 | npm |
setprototypeof | https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.0.2.tgz | 直接依赖 | npm |
pinkie-promise | https://registry.npmjs.org/pinkie-promise/-/pinkie-promise-2.0.1.tgz | 直接依赖 | npm |
stat-mode | https://registry.npm.taobao.org/stat-mode/download/stat-mode-0.2.2.tgz | 直接依赖 | npm |
clone | https://registry.npmjs.org/clone/-/clone-1.0.2.tgz | 直接依赖 | npm |
unpipe | https://registry.npmjs.org/unpipe/-/unpipe-1.0.0.tgz | 直接依赖 | npm |
install | https://registry.npmjs.org/install/-/install-0.8.7.tgz | 直接依赖 | npm |
random-bytes | https://registry.npmjs.org/random-bytes/-/random-bytes-1.0.0.tgz | 直接依赖 | npm |
async-arr | https://registry.npmjs.org/async-arr/-/async-arr-1.0.0.tgz | 直接依赖 | npm |
assert-plus | https://registry.npm.taobao.org/assert-plus/download/assert-plus-0.2.0.tgz | 直接依赖 | npm |
generate-object-property | https://registry.npm.taobao.org/generate-object-property/download/generate-object-property-1.2.0.tgz | 直接依赖 | npm |
uuid | https://registry.npmjs.org/uuid/-/uuid-3.0.1.tgz | 直接依赖 | npm |
media-typer | https://registry.npmjs.org/media-typer/-/media-typer-0.3.0.tgz | 直接依赖 | npm |
extend | https://registry.npmjs.org/extend/-/extend-3.0.0.tgz | 直接依赖 | npm |
verror | https://registry.npm.taobao.org/verror/download/verror-1.3.6.tgz | 直接依赖 | npm |
path-to-regexp | https://registry.npm.taobao.org/path-to-regexp/download/path-to-regexp-0.1.7.tgz | 直接依赖 | npm |
mysqldump | https://registry.npmjs.org/mysqldump/-/mysqldump-1.3.1.tgz | 直接依赖 | npm |
ansi-styles | https://registry.npmjs.org/ansi-styles/-/ansi-styles-2.2.1.tgz | 直接依赖 | npm |
mime-db | https://registry.npmjs.org/mime-db/-/mime-db-1.25.0.tgz | 直接依赖 | npm |
yauzl | https://registry.npmjs.org/yauzl/-/yauzl-2.4.1.tgz | 直接依赖 | npm |
stringstream | https://registry.npm.taobao.org/stringstream/download/stringstream-0.0.5.tgz | 直接依赖 | npm |
crypt | https://registry.npmjs.org/crypt/-/crypt-0.0.2.tgz | 直接依赖 | npm |
tar-stream | https://registry.npm.taobao.org/tar-stream/download/tar-stream-1.5.2.tgz | 直接依赖 | npm |
ms | https://registry.npmjs.org/ms/-/ms-0.7.1.tgz | 直接依赖 | npm |
request | https://registry.npmjs.org/request/-/request-2.79.0.tgz | 直接依赖 | npm |