CVE-2013-7377

The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
codem-transcode_projectcodem-transcode
0.4.1
codem-transcode_projectcodem-transcode
0.4.2
codem-transcode_projectcodem-transcode
0.4.3
codem-transcode_projectcodem-transcode
0.4.4
codem-transcode_projectcodem-transcode
0.5.0:beta1
codem-transcode_projectcodem-transcode
0.5.0:beta2
codem-transcode_projectcodem-transcode
0.5.0:beta3
codem-transcode_projectcodem-transcode
0.5.0:beta4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nodejs
bionic
ignored
artful
ignored
zesty
ignored
yakkety
ignored
xenial
ignored
wily
ignored
vivid
ignored
utopic
ignored
trusty
ignored
saucy
ignored
precise
ignored
lucid
dne