VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 41 of 192
  • CVE-2020-9582CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.06

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-14472CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.03

    On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.

  • CVE-2020-10561CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.

  • CVE-2020-12782CriJun 23, 2020
    risk 0.64cvss 9.8epss 0.02

    Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.

  • CVE-2020-8171CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.04

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that…

  • CVE-2019-5623CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

  • CVE-2020-11789CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

  • CVE-2018-11106CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running…

  • CVE-2019-15609CriFeb 28, 2020
    risk 0.64cvss 9.8epss 0.04

    The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

  • CVE-2020-3760CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.07

    Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2014-4982CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.05

    LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

  • CVE-2019-8255CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.07

    Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2018-0730CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2018-0729CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

  • CVE-2019-18780CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.06

    An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance…

  • CVE-2019-8088CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-1584CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.03

    A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.

  • CVE-2019-12736CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.02

    JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.

  • CVE-2019-8073CriSep 27, 2019
    risk 0.64cvss 9.8epss 0.08

    ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.

  • CVE-2019-7968CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.07

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.