CVE-2019-10787

im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:dnt:im-resize:*:*:*:*:*:node.js:*:*

Information

Published : 2020-02-04 13:15

Updated : 2020-08-24 10:37


NVD link : CVE-2019-10787

Mitre link : CVE-2019-10787


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

dnt

  • im-resize