Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The extract_from_ocr function in lib/docsplit/text_extractor.rb in the Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a PDF filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Karteek Docsplit for Ruby ‘extract_from_ocr’函数任意命令执行漏洞
Vulnerability Description
Karteek Docsplit (karteek-docsplit)是命令行工具和分割文档的Ruby库。 Karteek Docsplit (karteek-docsplit) gem 0.5.4 for Ruby中的lib/docsplit/text_extractor.rb中的‘extract_from_ocr’函数中存在漏洞。上下文相关的攻击者可通过PDF文件名中的shell元字符利用该漏洞执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A