Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4991

Опубликовано: 28 июл. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nodepdf_project:nodepdf:1.3.0:*:*:*:*:node.js:*:*

EPSS

Процентиль: 79%
0.01235
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-77

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

EPSS

Процентиль: 79%
0.01235
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77
CWE-77