VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 61 of 192
  • CVE-2024-54660HigJan 16, 2025
    risk 0.57cvss 8.7epss 0.01

    A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to…

  • CVE-2024-51442HigJan 8, 2025
    risk 0.57cvss 8.8epss 0.02

    Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

  • CVE-2024-39703HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.

  • CVE-2024-51114HigDec 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file

  • CVE-2024-11665HigNov 24, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.

  • CVE-2024-38644HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

  • CVE-2023-24467HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2021-38117HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2021-38116HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

  • CVE-2024-50853HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

  • CVE-2024-50852HigNov 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

  • CVE-2024-51254HigOct 31, 2024
    risk 0.57cvss 8.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

  • CVE-2024-51258HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.

  • CVE-2024-51301HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

  • CVE-2024-51300HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

  • CVE-2024-51299HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

  • CVE-2024-51296HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.

  • CVE-2024-51257HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

  • CVE-2024-51304HigOct 30, 2024
    risk 0.57cvss 8.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

  • CVE-2024-48441HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.