CVE-2016-10320
06.04.2017, 18:59
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
| Vendor | Product | Version |
|---|---|---|
| textract_project | textract | 𝑥 ≤ 1.4.0 |
𝑥
= Vulnerable software versions