Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
npm-dependency-versio 操作系统命令注入漏洞
Vulnerability Description
npm-dependency-versio是nmap得依赖插件。 npm-dependency-versions存在操作系统命令注入漏洞,该漏洞源于如果攻击者能够使用以 pkgs为键且值中有shell元字符的 JSON 对象调用dependencyVersions,则从 Node.js 到 0.3.0 的 npm-dependency-versions 包允许命令注入。
CVSS Information
N/A
Vulnerability Type
N/A