Логотип exploitDog
bind:CVE-2021-23355
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-23355

Количество 2

Количество 2

nvd логотип

CVE-2021-23355

почти 5 лет назад

This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file. PoC (provided by reporter): var ps_kill = require('ps-kill'); ps_kill.kill('$(touch success)',function(){});

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-7qmm-q394-fmch

почти 5 лет назад

Command Injection in ps-kill

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-23355

This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file. PoC (provided by reporter): var ps_kill = require('ps-kill'); ps_kill.kill('$(touch success)',function(){});

CVSS3: 5.6
1%
Низкий
почти 5 лет назад
github логотип
GHSA-7qmm-q394-fmch

Command Injection in ps-kill

CVSS3: 9.8
1%
Низкий
почти 5 лет назад

Уязвимостей на страницу