VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 23 of 199
  • CVE-2023-36103CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

  • CVE-2024-44410CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

  • CVE-2024-44402CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

  • CVE-2024-44401CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

  • CVE-2024-8073CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.

  • CVE-2024-44382CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

  • CVE-2024-44381CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

  • CVE-2024-42947CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2024-5914CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

  • CVE-2024-21878CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and…

  • CVE-2024-41319CriJul 23, 2024
    risk 0.64cvss 9.8epss 0.06

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

  • CVE-2024-41318CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

  • CVE-2024-41316CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

  • CVE-2024-40110CriJul 12, 2024
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.

  • CVE-2024-39028CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

  • CVE-2024-37091CriJun 24, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a…

  • CVE-2024-36604CriJun 4, 2024
    risk 0.64cvss 9.8epss 0.02

    Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary commands with root privileges.

  • CVE-2024-36783CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2024-4267CriMay 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of special elements used in a command within the 'open_file' function. An attacker…

  • CVE-2024-32353CriMay 14, 2024
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.