VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 22 of 191
  • CVE-2024-44382CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

  • CVE-2024-44381CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

  • CVE-2024-42947CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2024-5914CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

  • CVE-2024-21878CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and…

  • CVE-2024-41319CriJul 23, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

  • CVE-2024-41318CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2024-41316CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

  • CVE-2024-40110CriJul 12, 2024
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.

  • CVE-2024-39028CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

  • CVE-2024-37091CriJun 24, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a…

  • CVE-2024-36604CriJun 4, 2024
    risk 0.64cvss 9.8epss 0.02

    Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

  • CVE-2024-36783CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2024-4267CriMay 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker…

  • CVE-2024-32353CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

  • CVE-2024-34204CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.

  • CVE-2024-33789CriMay 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.

  • CVE-2024-0740CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is included in Eclipse IDE 2024-03

  • CVE-2024-22061CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.04

    A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands

  • CVE-2024-3871CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.02

    The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote…