npm heroku-env是美国npm公司的一个包。用于从 heroku 配置中解析 DATABASE_URL 并将其拆分为 psql pg_dump pg_restore 和 node_postgres 使用的 PG* 环境变量。 heroku-env 2.0.2之前版本存在命令注入漏洞,该漏洞源于存在命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | image-tiler | unspecified ~ 2.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-28423 | 9.8 CRITICAL | Command Injection |
| CVE-2020-28453 | 9.4 CRITICAL | Command Injection |
| CVE-2020-28437 | 9.4 CRITICAL | Command Injection |
| CVE-2020-28434 | 9.4 CRITICAL | Command Injection |
| CVE-2022-25867 | 7.5 HIGH | NULL Pointer Dereference |
| CVE-2020-7795 | 7.3 HIGH | Command Injection |
| CVE-2020-28433 | 7.3 HIGH | Command Injection |
| CVE-2020-28425 | 7.3 HIGH | Command Injection |
| CVE-2020-28424 | 7.2 HIGH | Command Injection |
| CVE-2021-23385 | 5.4 MEDIUM | Open Redirect |
| CVE-2022-34953 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-37035 | FRRouting FRR 竞争条件问题漏洞 | |
| CVE-2022-35422 | Web Based Quiz System SQL注入漏洞 | |
| CVE-2022-34954 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-34955 | Pligg CMS SQL注入漏洞 | |
| CVE-2022-34952 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-34950 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-34951 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-34949 | Pharmacy Management System SQL注入漏洞 | |
| CVE-2022-34948 | Pharmacy Management System SQL注入漏洞 |
Showing top 20 of 38 CVEs. View all on vendor page → →
No comments yet