漏洞标题
paginator(hex)中的远程代码执行
漏洞描述信息
远程代码执行在paginator(hex)中
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Remote Code Execution in paginator(hex)
漏洞描述信息
There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version 1.0.0. The vulnerability has been patched in version 1.0.0 and all users should upgrade to this version immediately. Note that this patched version uses a dependency that requires an Elixir version >=1.5.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
漏洞类别
对生成代码的控制不恰当(代码注入)
漏洞标题
Paginator Elixir/Hex 代码注入漏洞
漏洞描述信息
Paginator Elixir/Hex是一个应用软件。一个分页器。 Paginator(Elixir/Hex包)中存在代码注入漏洞,攻击者通过注入paginate()函数的输入参数进而执行远程代码。
CVSS信息
N/A
漏洞类别
代码注入