VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 67 of 192
  • CVE-2022-4009HigMar 16, 2023
    risk 0.57cvss 8.8epss 0.01

    In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation

  • CVE-2023-0351HigMar 13, 2023
    risk 0.57cvss 8.8epss 0.01

    The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions.

  • CVE-2023-0093HigMar 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an…

  • CVE-2021-3855HigMar 1, 2023
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0…

  • CVE-2023-23294HigFeb 23, 2023
    risk 0.57cvss 8.8epss 0.03

    Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.

  • CVE-2023-23917HigFeb 23, 2023
    risk 0.57cvss 8.8epss 0.01

    A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack…

  • CVE-2022-45600HigFeb 22, 2023
    risk 0.57cvss 8.8epss 0.02

    Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal…

  • CVE-2023-25805CriFeb 20, 2023
    risk 0.57cvss 9.8epss 0.02

    versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0.

  • CVE-2022-45104HigFeb 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying…

  • CVE-2022-41955HigJan 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A remote code execution vulnerability was discovered in Autolab's…

  • CVE-2022-32664HigJan 3, 2023
    risk 0.57cvss 8.8epss 0.01

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Patch ID: A20220004; Issue ID: OSBNB00140929.

  • CVE-2022-44621CriDec 30, 2022
    risk 0.57cvss 9.8epss 0.03

    Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

  • CVE-2020-15685HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.

  • CVE-2022-46421CriDec 20, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.

  • CVE-2022-45907CriNov 26, 2022
    risk 0.57cvss 9.8epss 0.01

    In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

  • CVE-2022-45462CriNov 23, 2022
    risk 0.57cvss 9.8epss 0.03

    Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher

  • CVE-2022-45063CriNov 10, 2022
    risk 0.57cvss 9.8epss 0.05

    xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

  • CVE-2022-42161HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.03

    D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS.

  • CVE-2022-42160HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.03

    D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.

  • CVE-2022-42156HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.03

    D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.