CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 67 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4009 | Hig | 0.57 | 8.8 | 0.01 | Mar 16, 2023 | In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation | ||
| CVE-2023-0351 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2023 | The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions. | ||
| CVE-2023-0093 | Hig | 0.57 | 8.8 | 0.01 | Mar 6, 2023 | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an… | ||
| CVE-2021-3855 | Hig | 0.57 | 8.8 | 0.02 | Mar 1, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0… | ||
| CVE-2023-23294 | Hig | 0.57 | 8.8 | 0.03 | Feb 23, 2023 | Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root. | ||
| CVE-2023-23917 | Hig | 0.57 | 8.8 | 0.01 | Feb 23, 2023 | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack… | ||
| CVE-2022-45600 | Hig | 0.57 | 8.8 | 0.02 | Feb 22, 2023 | Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal… | ||
| CVE-2023-25805 | Cri | 0.57 | 9.8 | 0.02 | Feb 20, 2023 | versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0. | ||
| CVE-2022-45104 | Hig | 0.57 | 8.8 | 0.01 | Feb 11, 2023 | Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying… | ||
| CVE-2022-41955 | Hig | 0.57 | 8.8 | 0.01 | Jan 14, 2023 | Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A remote code execution vulnerability was discovered in Autolab's… | ||
| CVE-2022-32664 | Hig | 0.57 | 8.8 | 0.01 | Jan 3, 2023 | In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Patch ID: A20220004; Issue ID: OSBNB00140929. | ||
| CVE-2022-44621 | Cri | 0.57 | 9.8 | 0.03 | Dec 30, 2022 | Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | ||
| CVE-2020-15685 | Hig | 0.57 | 8.8 | 0.01 | Dec 22, 2022 | During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7. | ||
| CVE-2022-46421 | Cri | 0.57 | 9.8 | 0.03 | Dec 20, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0. | ||
| CVE-2022-45907 | Cri | 0.57 | 9.8 | 0.01 | Nov 26, 2022 | In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. | ||
| CVE-2022-45462 | Cri | 0.57 | 9.8 | 0.03 | Nov 23, 2022 | Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher | ||
| CVE-2022-45063 | Cri | 0.57 | 9.8 | 0.05 | Nov 10, 2022 | xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions. | ||
| CVE-2022-42161 | Hig | 0.57 | 8.8 | 0.03 | Oct 13, 2022 | D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS. | ||
| CVE-2022-42160 | Hig | 0.57 | 8.8 | 0.03 | Oct 13, 2022 | D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings. | ||
| CVE-2022-42156 | Hig | 0.57 | 8.8 | 0.03 | Oct 13, 2022 | D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings. |
- risk 0.57cvss 8.8epss 0.01
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
- risk 0.57cvss 8.8epss 0.01
The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions.
- risk 0.57cvss 8.8epss 0.01
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an…
- risk 0.57cvss 8.8epss 0.02
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0…
- risk 0.57cvss 8.8epss 0.03
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
- risk 0.57cvss 8.8epss 0.01
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack…
- risk 0.57cvss 8.8epss 0.02
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal…
- risk 0.57cvss 9.8epss 0.02
versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0.
- risk 0.57cvss 8.8epss 0.01
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying…
- risk 0.57cvss 8.8epss 0.01
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web. A remote code execution vulnerability was discovered in Autolab's…
- risk 0.57cvss 8.8epss 0.01
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Patch ID: A20220004; Issue ID: OSBNB00140929.
- risk 0.57cvss 9.8epss 0.03
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
- risk 0.57cvss 8.8epss 0.01
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7.
- risk 0.57cvss 9.8epss 0.03
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
- risk 0.57cvss 9.8epss 0.01
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
- risk 0.57cvss 9.8epss 0.03
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
- risk 0.57cvss 9.8epss 0.05
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
- risk 0.57cvss 8.8epss 0.03
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS.
- risk 0.57cvss 8.8epss 0.03
D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the system_time_timezone parameter at function SetNTPServerSettings.
- risk 0.57cvss 8.8epss 0.03
D-Link COVR 1200,1203 v1.08 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter at function SetNetworkTomographySettings.