Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:1526
HistoryMar 02, 2015 - 4:29 p.m.

Arbitrary Command Execution Through Shell Metacharacters In API Arguments

2015-03-0216:29:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.008 Low

EPSS

Percentile

82.2%

The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function. This vulnerability is a duplicate of CVE-2017-16100.

CPENameOperatorVersion
dns-synceq0.1.0

0.008 Low

EPSS

Percentile

82.2%