Vulnerabilities
Vulnerable Software
Traceroute Project:  >> Traceroute  Security Vulnerabilities
The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.
CVSS Score
10.0
EPSS Score
0.065
Published
2020-06-25


Contact Us

Shodan ® - All rights reserved