ppt2png 0.0.6 及更早版本存在操作系统命令注入漏洞,攻击者通过提供未经清理的输入或输出路径参数,可以执行操作系统命令。攻击者可以向 ppt2png.js 中调用 child_process.exec() 所传递的文件名中附加 Shell 元字符(例如“;”),从而以 Node.js 进程权限执行命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet