Логотип exploitDog
bind:CVE-2018-21268
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-21268

Количество 2

Количество 2

nvd логотип

CVE-2018-21268

больше 5 лет назад

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-8j9v-qhp4-wv55

больше 3 лет назад

Node-Traceroute RCE Vulnerability

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-21268

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

CVSS3: 10
7%
Низкий
больше 5 лет назад
github логотип
GHSA-8j9v-qhp4-wv55

Node-Traceroute RCE Vulnerability

CVSS3: 9.8
7%
Низкий
больше 3 лет назад

Уязвимостей на страницу