CVE-2013-7377

The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:codem-transcode_project:codem-transcode:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.4.3:*:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.4.4:*:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.5.0:beta1:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.5.0:beta2:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.5.0:beta3:*:*:*:*:*:*
cpe:2.3:a:codem-transcode_project:codem-transcode:0.5.0:beta4:*:*:*:*:*:*

History

21 Nov 2024, 02:00

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2014/05/13/1 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/05/13/1 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2014/05/15/2 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/05/15/2 - Mailing List, Third Party Advisory
References () https://nodesecurity.io/advisories/codem-transcode_command_injection - Third Party Advisory () https://nodesecurity.io/advisories/codem-transcode_command_injection - Third Party Advisory

Information

Published : 2017-10-23 18:29

Updated : 2024-11-21 02:00


NVD link : CVE-2013-7377

Mitre link : CVE-2013-7377

CVE.ORG link : CVE-2013-7377


JSON object : View

Products Affected

codem-transcode_project

  • codem-transcode
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')