ZeroHour

CVE-2018-21268

PoC ×2
CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

Vendors
traceroute project
Products
traceroute
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.