VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 39 of 192
  • CVE-2021-38611CriAug 24, 2021
    risk 0.64cvss 9.8epss 0.02

    A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.

  • CVE-2020-18758CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.

  • CVE-2021-36707CriAug 6, 2021
    risk 0.64cvss 9.8epss 0.03

    In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.

  • CVE-2021-32529CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-20699CriJun 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V…

  • CVE-2020-10666CriMay 31, 2021
    risk 0.64cvss 9.8epss 0.02

    The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.

  • CVE-2019-25029CriMay 26, 2021
    risk 0.64cvss 9.8epss 0.03

    In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP…

  • CVE-2020-28908CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.06

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

  • CVE-2020-28902CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.06

    Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

  • CVE-2020-28901CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.09

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

  • CVE-2020-20951CriMay 18, 2021
    risk 0.64cvss 9.8epss 0.04

    In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.

  • CVE-2021-25812CriApr 29, 2021
    risk 0.64cvss 9.8epss 0.03

    Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.

  • CVE-2021-31726CriApr 25, 2021
    risk 0.64cvss 9.8epss 0.02

    Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).

  • CVE-2021-20991CriApr 19, 2021
    risk 0.64cvss 9.8epss 0.05

    In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.

  • CVE-2021-23378CriApr 18, 2021
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23377CriApr 18, 2021
    risk 0.64cvss 9.8epss 0.03

    This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23376CriApr 18, 2021
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2020-27227CriApr 13, 2021
    risk 0.64cvss 9.8epss 0.03

    An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability,…

  • CVE-2021-26275CriMar 19, 2021
    risk 0.64cvss 9.8epss 0.03

    The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer GitHub repository has been intentionally…

  • CVE-2021-3148CriFeb 27, 2021
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.