Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Command Injection
Vulnerability Description
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Skoranga Node-connection-tester 命令注入漏洞
Vulnerability Description
Skoranga Node-connection-tester是Skoranga个人开发者的一个基于Javascript的用于测试远程主机和端口是否可以建立连接的软件。 connection-tester 0.2.1之前版本存在命令注入漏洞,该漏洞源于index.js的第15行。
CVSS Information
N/A
Vulnerability Type
N/A