漏洞描述 systeminformation 是Node.js 的一个获取系统信息和操作系统信息的库。Node.JS systeminformation 在 5.3.1版本之前存在远程命令注入漏洞。这个漏洞允许攻击者在特定条件下,通过精心构造的输入,执行任意命令。
相关漏洞推荐 CVE-2014-3744: Node.js st module Directory Traversal POC 2025-08-01 | Node.js A directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attacker... CVE-2017-14849: Node.js <8.6.0 - Directory Traversal POC 2025-08-01 | Node.js Node.js before 8.6.0 allows remote attackers to access unintended files because a change to "..... CVE-2021-21315: Node.JS System Information Library <5.3.1 - Remote Command Injection POC 2025-08-01 | Node.js System Information Library Node.JS System Information Library System before version 5.3.1 is susceptible to remote command inje... ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...