VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 66 of 192
  • CVE-2023-35032HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554.

  • CVE-2023-35031HigJun 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036.

  • CVE-2023-33533HigJun 6, 2023
    risk 0.57cvss 8.8epss 0.03

    Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains web management privileges, they can inject commands into…

  • CVE-2023-33530HigJun 6, 2023
    risk 0.57cvss 8.8epss 0.01

    There is a command injection vulnerability in the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker gains web management privileges, they can inject commands gaining shell privileges.

  • CVE-2023-33722HigMay 31, 2023
    risk 0.57cvss 8.8epss 0.02

    EDIMAX BR-6288ACL v1.12 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the pppUserName parameter.

  • CVE-2015-20108CriMay 27, 2023
    risk 0.57cvss 9.8epss 0.01

    xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

  • CVE-2023-31996HigMay 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Hanwha IP Camera ANE-L7012R 1.41.01 is vulnerable to Command Injection due to improper sanitization of special characters for the NAS storage test function.

  • CVE-2023-31701HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceRemove.

  • CVE-2023-31700HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WPA4530 KIT V2 (EU)_170406 and V2 (EU)_161115 is vulnerable to Command Injection via _httpRpmPlcDeviceAdd.

  • CVE-2023-31531HigMay 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.

  • CVE-2023-31530HigMay 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.

  • CVE-2023-31529HigMay 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.

  • CVE-2023-31528HigMay 11, 2023
    risk 0.57cvss 8.8epss 0.02

    Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.

  • CVE-2023-2520HigMay 4, 2023
    risk 0.57cvss 8.8epss 0.03

    A vulnerability was found in Caton Prime 2.1.2.51.e8d7225049(202303031001) and classified as critical. This issue affects some unknown processing of the file cgi-bin/tools_ping.cgi?action=Command of the component Ping Handler. The manipulation of the argument Destination leads…

  • CVE-2023-29566CriApr 24, 2023
    risk 0.57cvss 9.8epss 0.02

    huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

  • CVE-2023-1877CriApr 5, 2023
    risk 0.57cvss 9.8epss 0.02

    Command Injection in GitHub repository microweber/microweber prior to 1.3.3.

  • CVE-2023-28935HigMar 30, 2023
    risk 0.57cvss 8.8epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated…

  • CVE-2023-1141HigMar 27, 2023
    risk 0.57cvss 8.8epss 0.02

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a command injection vulnerability that could allow an attacker to inject arbitrary commands, which could result in remote code execution.

  • CVE-2018-25083CriMar 27, 2023
    risk 0.57cvss 9.8epss 0.03

    The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

  • CVE-2023-27796HigMar 26, 2023
    risk 0.57cvss 8.8epss 0.02

    RG-EW1200G PRO Wireless Routers EW_3.0(1)B11P204, RG-EW1800GX PRO Wireless Routers EW_3.0(1)B11P204, and RG-EW3200GX PRO Wireless Routers EW_3.0(1)B11P204 were discovered to contain multiple command injection vulnerabilities via the data.ip, data.protocal, data.iface and…