Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
N/A
Vulnerability Title
Module-ScanDeps 安全漏洞
Vulnerability Description
Module-ScanDeps是Roderich Schupp个人开发者的一个应用程序。 Module-ScanDeps 1.36之前版本存在安全漏洞,该漏洞源于输入验证不当,导致本地攻击者通过打开pesky pipe或向eval传递任意字符串来执行任意shell命令。
CVSS Information
N/A
Vulnerability Type
N/A