Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2020-7778
- EPSS 2.39%
- Veröffentlicht 26.11.2020 11:15:10
- Zuletzt bearbeitet 21.11.2024 05:37:47
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
6.5
CVE-2020-7752
- EPSS 5.78%
- Veröffentlicht 26.10.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:37:44
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.