VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 51 of 192
  • CVE-2024-34792CriJun 4, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This issue affects Dextaz Ping: from n/a through 0.65.

  • CVE-2024-2366CriMay 16, 2024
    risk 0.59cvss 9.0epss 0.01

    A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path…

  • CVE-2024-29385CriMar 22, 2024
    risk 0.59cvss 9.0epss 0.02

    DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

  • CVE-2024-25228HigMar 14, 2024
    risk 0.59cvss 8.8epss 0.26

    Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

  • CVE-2024-22127CriMar 12, 2024
    risk 0.59cvss 9.1epss 0.02

    SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause…

  • CVE-2024-1378CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability…

  • CVE-2024-1374CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.03

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this…

  • CVE-2024-1372CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the…

  • CVE-2024-1369CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this…

  • CVE-2024-1359CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the…

  • CVE-2024-1355CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of…

  • CVE-2023-45025CriFeb 2, 2024
    risk 0.59cvss 9.0epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build…

  • CVE-2024-0919HigJan 26, 2024
    risk 0.59cvss 8.8epss 0.23

    A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate…

  • CVE-2024-23628CriJan 26, 2024
    risk 0.59cvss 9.0epss 0.03

    A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

  • CVE-2024-23627CriJan 26, 2024
    risk 0.59cvss 9.0epss 0.04

    A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

  • CVE-2024-23626CriJan 26, 2024
    risk 0.59cvss 9.0epss 0.04

    A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.

  • CVE-2023-21413CriOct 16, 2023
    risk 0.59cvss 9.1epss 0.01

    GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary…

  • CVE-2023-44959HigOct 10, 2023
    risk 0.59cvss 8.8epss 0.21

    An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.

  • CVE-2023-36755CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36754CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…