OS Command Injection via Filename in Textract before 1.5.0

OS Command Injection via Filename in Textract before 1.5.0

CVE-2016-10320 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.

Learn more about our Web App Pen Testing.