VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 100 of 192
  • CVE-2020-22570HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

  • CVE-2023-28130HigJul 26, 2023
    risk 0.49cvss 7.2epss 0.21

    Local user may lead to privilege escalation using Gaia Portal hostnames page.

  • CVE-2023-31476HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an empty file can be created almost anywhere on the filesystem, as long as the filename and path is no more than 6 characters (the working directory is /www).

  • CVE-2023-27079HigMar 23, 2023
    risk 0.49cvss 7.5epss 0.02

    Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package

  • CVE-2023-1162HigMar 3, 2023
    risk 0.49cvss 7.2epss 0.26

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an unknown function of the file mainfunction.cgi of the component Web Management Interface. The manipulation of the argument password…

  • CVE-2023-0861HigFeb 16, 2023
    risk 0.49cvss 7.2epss 0.29

    NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119,…

  • CVE-2022-43758HigFeb 7, 2023
    risk 0.49cvss 7.6epss 0.01

    A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users…

  • CVE-2020-22662HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300)…

  • CVE-2022-35271HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-35270HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-35269HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-35267HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-35266HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-35265HigOct 25, 2022
    risk 0.49cvss 7.5epss 0.01

    A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to denial of service. An attacker can send a sequence of requests to trigger this vulnerability.This denial of…

  • CVE-2022-28220HigSep 8, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into account concurrent…

  • CVE-2022-30321HigMay 25, 2022
    risk 0.49cvss 8.6epss 0.03

    go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.

  • CVE-2021-43663HigMar 31, 2022
    risk 0.49cvss 7.5epss 0.01

    totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.

  • CVE-2021-45557HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GC108P before 1.0.8.2, GC108PP before 1.0.8.2, GS108Tv3 before 7.0.7.2, GS110TPv3 before 7.0.7.2, GS110TPP before 7.0.7.2, GS110TUP before 1.0.5.3, GS710TUP before 1.0.5.3, GS308T…

  • CVE-2021-45556HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.36, GS110TPP before 7.0.7.2, GS110TPv2 before 5.4.2.36., GS110TPv3 before 7.0.7.2, GS308T before 1.0.3.2, GS310TP before 1.0.3.2, GS724TPP before 2.0.6.3,…

  • CVE-2021-40345HigOct 26, 2021
    risk 0.49cvss 7.2epss 0.23

    An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.