getID3 在 1.9.26 之前版本中存在操作系统命令注入漏洞,该漏洞源于 shell 外调处理程序(shell-out handlers)未对文件名中的特殊字符进行转义。攻击者可以构造包含 shell 元字符的恶意文件名,从而注入任意命令,这些命令将以嵌入 getID3 的进程的权限执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| james-heinrich | getid3 | 0 ~ 1.9.26 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet