Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
is-http2 操作系统命令注入漏洞
Vulnerability Description
is-http2是Stefan Judis个人开发者的一个应用程序。用于检查某些服务器是否支持 HTTP/2 的简单模块。 is-http2存在操作系统命令注入漏洞,该漏洞源于缺少输入清理或其他检查以及isH2函数使用沙箱,存在命令注入。
CVSS Information
N/A
Vulnerability Type
N/A