Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Thumbler 安全漏洞
Vulnerability Description
Thumbler是Mohamed Mahrous Sayed个人开发者的一个视频与图像缩略图提取工具。 thumbler 1.1.2及之前版本存在安全漏洞,该漏洞源于thumbnail函数中input、output、time或size参数未经验证,可能导致OS命令注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A