The traceroute (aka node-traceroute) package up to and including 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
traceroute project traceroute |