CVE-2016-10320
EUVD-2016-150506.04.2017, 18:59
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| textract_project | textract | 𝑥 ≤ 1.4.0 |
𝑥
= Vulnerable software versions