Описание
files.photo.gallery command injection
A command injection vulnerability in the video thumbnail rendering component of files.photo.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.
Пакеты
Наименование
files.photo.gallery
npm
Затронутые версииВерсия исправления
>= 0.3.0, <= 0.11.0
Отсутствует
Связанные уязвимости
CVSS3: 6.5
nvd
около 1 года назад
A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.