dot-access 0.0.3 至 1.0.0 版本存在代码注入漏洞,远程攻击者可通过向 get() 方法提供精心构造的路径来执行 JavaScript 代码。在 index.js 中,该路径被拼接进 new Function 的代码体中,攻击者借此可访问 constructor.constructor,从而加载 child_process 模块,并在 Node.js 进程中执行操作系统命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ntharim | dot-access | 0.0.3≤ 1.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ntharim | dot-access | 0.0.3 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet