VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 54 of 192
  • CVE-2023-23295HigFeb 23, 2023
    risk 0.58cvss 8.8epss 0.04

    Korenix Jetwave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection via /goform/formSysCmd. An attacker an modify the sysCmd parameter in order to execute commands as root.

  • CVE-2023-0611HigFeb 1, 2023
    risk 0.58cvss 8.8epss 0.04

    A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation leads to command injection. The attack may be…

  • CVE-2023-22884CriJan 21, 2023
    risk 0.58cvss 9.8epss 0.11

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL…

  • CVE-2022-40282HigNov 25, 2022
    risk 0.58cvss 8.8epss 0.04

    The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The…

  • CVE-2020-36529HigJun 7, 2022
    risk 0.58cvss 8.8epss 0.04

    A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the…

  • CVE-2022-26085HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.13

    An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2022-26042HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.09

    An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-44520HigApr 13, 2022
    risk 0.58cvss 8.8epss 0.06

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

  • CVE-2019-16864HigFeb 14, 2022
    risk 0.58cvss 8.8epss 0.08

    CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.

  • CVE-2021-32849HigJan 26, 2022
    risk 0.58cvss 8.8epss 0.08

    Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.

  • CVE-2020-19151HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.05

    Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

  • CVE-2021-38556HigAug 24, 2021
    risk 0.58cvss 8.8epss 0.13

    includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.

  • CVE-2020-10580HigMar 25, 2021
    risk 0.58cvss 8.8epss 0.04

    A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the application.

  • CVE-2020-8298CriMar 4, 2021
    risk 0.58cvss 9.8epss 0.11

    fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.

  • CVE-2020-27864HigFeb 12, 2021
    risk 0.58cvss 8.8epss 0.10

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service,…

  • CVE-2020-15642HigAug 25, 2020
    risk 0.58cvss 8.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The…

  • CVE-2020-8233HigAug 17, 2020
    risk 0.58cvss 8.8epss 0.04

    A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.

  • CVE-2019-16305HigSep 14, 2019
    risk 0.58cvss 8.8epss 0.07

    In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appears asking for further confirmation. If this is also…

  • CVE-2019-7989HigAug 26, 2019
    risk 0.58cvss 8.8epss 0.14

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-12104HigAug 14, 2019
    risk 0.58cvss 8.8epss 0.05

    The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities.