ohmyzsh是一个开源的、社区驱动的框架,用于管理您的zsh配置。 ohmyzsh 存在操作系统命令注入漏洞,攻击者可以利用该漏洞通过rand-quote和hitokoto插件触发命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ohmyzsh | ohmyzsh/ohmyzsh | unspecified ~ 72928432 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-3725 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3726 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
| CVE-2021-3769 | 7.5 HIGH | OS Command Injection in ohmyzsh/ohmyzsh |
No comments yet