ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28429”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28429
Published
2021-02-23
CVSS:
7.3
ShadowTrackr CVSS:
2.9
Summary:
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})