Description
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
Remediation
References
http://www.openwall.com/lists/oss-security/2014/05/13/1
http://www.openwall.com/lists/oss-security/2014/05/15/2
https://nodesecurity.io/advisories/codem-transcode_command_injection
Related Vulnerabilities
CVE-2022-24898 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2020-15215 Vulnerability in npm package electron
CVE-2020-7749 Vulnerability in npm package osm-static-maps
CVE-2021-37404 Vulnerability in maven package org.apache.hadoop:hadoop-hdfs-native-client
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri