VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 195 of 199
  • CVE-2024-51736NonNov 6, 2024
    risk 0.00cvss 0.0epss 0.00

    Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments,…

  • CVE-2024-9287HigOct 22, 2024
    risk 0.00cvss 7.8epss 0.01

    A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This…

  • CVE-2024-46256CriSep 27, 2024
    risk 0.00cvss 9.8epss 0.03

    A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

  • CVE-2024-25639MedJul 8, 2024
    risk 0.00cvss 5.9epss 0.01

    Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user…

  • CVE-2024-37385CriJun 7, 2024
    risk 0.00cvss 9.8epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

  • CVE-2024-32027CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

  • CVE-2024-32026CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32025CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.02

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32022CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.

  • CVE-2024-29864CriMar 21, 2024
    risk 0.00cvss 9.8epss 0.03

    Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.

  • CVE-2024-25082MedFeb 26, 2024
    risk 0.00cvss 6.5epss 0.02

    Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

  • CVE-2024-25081MedFeb 26, 2024
    risk 0.00cvss 4.2epss 0.01

    Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

  • CVE-2024-21663CriJan 9, 2024
    risk 0.00cvss 9.9epss 0.02

    Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role.…

  • CVE-2023-6848HigDec 16, 2023
    risk 0.00cvss 7.3epss 0.02

    A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of the argument soffice leads to command…

  • CVE-2023-48702HigDec 13, 2023
    risk 0.00cvss 7.2epss 0.01

    Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file using `ProcessStartInfo` via the `ValidateVersion` function. A malicious administrator can setup a network share and supply a UNC…

  • CVE-2023-39008CriAug 9, 2023
    risk 0.00cvss 9.8epss 0.03

    A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.

  • CVE-2023-39001CriAug 9, 2023
    risk 0.00cvss 9.8epss 0.04

    A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.

  • CVE-2023-26130HigMay 30, 2023
    risk 0.00cvss 7.5epss 0.01

    Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:**…

  • CVE-2022-37704MedApr 16, 2023
    risk 0.00cvss 6.7epss 0.01

    Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead to escalation of privileges, denial of service, and…

  • CVE-2023-28854HigApr 3, 2023
    risk 0.00cvss 8.0epss 0.02

    nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A patch was made available at commit e5409aa2d441789cbb35f6b119bef97ecc3986aa on 2023-03-30. Users should update index.php to 2023-03-30 or later or, as a…