VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 42 of 199
  • CVE-2020-13917CriJul 28, 2020
    risk 0.64cvss 9.8epss 0.02

    rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s,…

  • CVE-2020-14505CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.07

    Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command…

  • CVE-2020-8186CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.

  • CVE-2020-9583CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.06

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9582CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.06

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-14472CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.03

    On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.

  • CVE-2020-10561CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.

  • CVE-2020-12782CriJun 23, 2020
    risk 0.64cvss 9.8epss 0.02

    Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files.

  • CVE-2020-8171CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.04

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that…

  • CVE-2019-5623CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

  • CVE-2020-11789CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

  • CVE-2018-11106CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.03

    NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running…

  • CVE-2019-15609CriFeb 28, 2020
    risk 0.64cvss 9.8epss 0.04

    The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.

  • CVE-2020-3760CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.07

    Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2014-4982CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.05

    LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

  • CVE-2019-8255CriDec 19, 2019
    risk 0.64cvss 9.8epss 0.07

    Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2018-0730CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2018-0729CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

  • CVE-2019-18780CriNov 5, 2019
    risk 0.64cvss 9.8epss 0.06

    An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance…

  • CVE-2019-8088CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.