VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 168 of 199
  • CVE-2023-36457MedJul 5, 2023
    risk 0.41cvss 6.3epss 0.02

    1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6.

  • CVE-2023-34232HigJun 8, 2023
    risk 0.41cvss 7.3epss 0.02

    snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1)…

  • CVE-2023-2682MedMay 12, 2023
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/ping.cgi of the component Mini_HTTPD. The manipulation of the argument address with the input ;id;uname${IFS}-a leads to command…

  • CVE-2023-1685MedMar 29, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection. The attack can be initiated remotely.…

  • CVE-2023-0649MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of the file /home/sendBroadcast. The manipulation of the argument message leads to command injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2023-0648MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the file /home/masterConsole. The manipulation of the argument command leads to command injection. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2023-0647MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, has been found in dst-admin 1.5.0. Affected by this issue is some unknown functionality of the file /home/kickPlayer. The manipulation of the argument userId leads to command injection. The attack may be launched remotely. The…

  • CVE-2023-0646MedFeb 2, 2023
    risk 0.41cvss 6.3epss 0.03

    A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functionality of the file /home/cavesConsole. The manipulation of the argument command leads to command injection. The attack can be launched remotely. The exploit…

  • CVE-2022-25916HigFeb 1, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

  • CVE-2022-21129HigJan 31, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium…

  • CVE-2022-21191HigJan 13, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

  • CVE-2022-25923HigJan 6, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

  • CVE-2022-25926HigJan 4, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

  • CVE-2022-24377HigDec 14, 2022
    risk 0.41cvss 7.4epss 0.02

    The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

  • CVE-2022-20926MedNov 15, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of…

  • CVE-2022-20925MedNov 15, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of…

  • CVE-2020-7795HigAug 2, 2022
    risk 0.41cvss 7.3epss 0.04

    The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.

  • CVE-2021-45552MedDec 26, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 before 1.0.1.20.

  • CVE-2021-45548MedDec 26, 2021
    risk 0.41cvss 6.3epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.60, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6200v2 before 1.0.1.86, EX6250 before 1.0.0.128, EX6400 before 1.0.2.144, EX6400v2…

  • CVE-2021-40995MedOct 15, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Manager 6.8.x prior to 6.8.9-HF1. Aruba has…