total.js是开源的一个采用JavaScript开发用于Node.js平台的框架。它能够用于开发web、桌面、服务和IoT平台。 total.js 0e5ace7之前版本存在操作系统命令注入漏洞,该漏洞源于/api/common/ping可以通过host参数中的shell元字符实现远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-42777 | Stimulsoft 安全漏洞 | |
| CVE-2022-41973 | Red Hat device-mapper-multipath 后置链接漏洞 | |
| CVE-2022-41974 | Red Hat device-mapper-multipath 安全漏洞 | |
| CVE-2022-42915 | curl 资源管理错误漏洞 | |
| CVE-2022-42916 | curl 安全漏洞 | |
| CVE-2022-44020 | OpenStack 安全漏洞 | |
| CVE-2022-44022 | PwnDoc 授权问题漏洞 | |
| CVE-2022-44023 | PwnDoc 安全漏洞 |
No comments yet