VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 162 of 192
  • CVE-2024-5355MedMay 26, 2024
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2024-32282MedApr 17, 2024
    risk 0.41cvss 6.3epss 0.01

    Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

  • CVE-2024-21488HigJan 30, 2024
    risk 0.41cvss 7.3epss 0.03

    Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for…

  • CVE-2024-0579MedJan 16, 2024
    risk 0.41cvss 6.3epss 0.02

    A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be…

  • CVE-2024-0291MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to command injection. The attack may be…

  • CVE-2023-51664HigDec 27, 2023
    risk 0.41cvss 7.3epss 0.03

    tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue…

  • CVE-2023-26145HigSep 28, 2023
    risk 0.41cvss 7.4epss 0.03

    This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths…

  • CVE-2023-3739MedAug 1, 2023
    risk 0.41cvss 6.3epss 0.00

    Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a remote attacker to execute arbitrary code via a crafted shell script. (Chromium security severity: Low)

  • CVE-2023-36458MedJul 5, 2023
    risk 0.41cvss 6.3epss 0.02

    1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulnerability has been fixed in v1.3.6.

  • CVE-2023-36457MedJul 5, 2023
    risk 0.41cvss 6.3epss 0.02

    1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6.

  • CVE-2023-34232HigJun 8, 2023
    risk 0.41cvss 7.3epss 0.02

    snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1)…

  • CVE-2023-2682MedMay 12, 2023
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${IFS}-a leads to command…

  • CVE-2023-1685MedMar 29, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely.…

  • CVE-2023-0649MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2023-0648MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2023-0647MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, has been found in dst-admin 1.5.0. Affected by this issue is some unknown functionality of the file /home/kickPlayer. The manipulation of the argument userId leads to command injection. The attack may be launched remotely. The…

  • CVE-2023-0646MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functionality of the file /home/cavesConsole. The manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit…

  • CVE-2022-25916HigFeb 1, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

  • CVE-2022-21129HigJan 31, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium…

  • CVE-2022-21191HigJan 13, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.