VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 189 of 191
  • CVE-2021-44079CriNov 22, 2021
    risk 0.00cvss 9.8epss 0.03

    In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

  • CVE-2020-36451HigAug 8, 2021
    risk 0.00cvss 8.1epss 0.01

    An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell.

  • CVE-2021-38173CriAug 7, 2021
    risk 0.00cvss 9.8epss 0.03

    Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.

  • CVE-2021-29501HigMay 10, 2021
    risk 0.00cvss 8.1epss 0.01

    Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive information has been found in the Ticketer cog. Please upgrade to version 1.0.1 as soon as possible. As a workaround users may unload the…

  • CVE-2021-29154HigApr 8, 2021
    risk 0.00cvss 7.8epss 0.01

    BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.

  • CVE-2021-26541CriFeb 8, 2021
    risk 0.00cvss 9.8epss 0.05

    The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.

  • CVE-2021-23330CriFeb 1, 2021
    risk 0.00cvss 9.8epss 0.05

    All versions of package launchpad are vulnerable to Command Injection via stop.

  • CVE-2020-26273MedDec 16, 2020
    risk 0.00cvss 5.2epss 0.01

    osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. In osquery before version 4.6.0, by using sqlite's ATTACH verb, someone with administrative access to osquery can cause reads and writes to arbitrary sqlite databases on disk. This…

  • CVE-2020-28247MedNov 12, 2020
    risk 0.00cvss 5.3epss 0.02

    The lettre library through 0.10.0-alpha for Rust allows arbitrary sendmail option injection via transport/sendmail/mod.rs.

  • CVE-2020-11073HigMay 13, 2020
    risk 0.00cvss 7.9epss 0.01

    In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0

  • CVE-2019-14868HigApr 2, 2020
    risk 0.00cvss 7.4epss 0.01

    In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to…

  • CVE-2019-14745HigAug 7, 2019
    risk 0.00cvss 7.8epss 0.04

    In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of…

  • CVE-2018-9866CriAug 3, 2018
    risk 0.00cvss 9.8epss 0.04

    A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8.1 and earlier.

  • CVE-2015-6613Nov 3, 2015
    risk 0.00cvss epss 0.01

    Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 24371736.

  • CVE-2015-5011Oct 26, 2015
    risk 0.00cvss epss 0.00

    IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

  • CVE-2015-4974Oct 26, 2015
    risk 0.00cvss epss 0.01

    IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

  • CVE-2015-4930Oct 4, 2015
    risk 0.00cvss epss 0.02

    IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.

  • CVE-2015-2011Oct 4, 2015
    risk 0.00cvss epss 0.02

    The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

  • CVE-2015-6547Sep 20, 2015
    risk 0.00cvss epss 0.04

    The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.

  • CVE-2015-5274Sep 18, 2015
    risk 0.00cvss epss 0.02

    rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.