CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,834)
page 70 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42740 | Cri | 0.57 | 9.8 | 0.04 | Oct 21, 2021 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command… | ||
| CVE-2021-34748 | Hig | 0.57 | 8.8 | 0.03 | Oct 6, 2021 | A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. An attacker could… | ||
| CVE-2021-36162 | Hig | 0.57 | 8.8 | 0.02 | Sep 7, 2021 | Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order to find the right… | ||
| CVE-2020-19001 | Cri | 0.57 | 9.8 | 0.04 | Aug 27, 2021 | Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'. | ||
| CVE-2021-38189 | Cri | 0.57 | 9.8 | 0.01 | Aug 8, 2021 | An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two sequences and then inject arbitrary SMTP commands. | ||
| CVE-2021-38169 | Hig | 0.57 | 8.8 | 0.02 | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py. | ||
| CVE-2020-17759 | Hig | 0.57 | 8.8 | 0.03 | Jun 24, 2021 | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941. | ||
| CVE-2020-21785 | Hig | 0.57 | 8.8 | 0.03 | Jun 24, 2021 | In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability. | ||
| CVE-2021-28812 | Hig | 0.57 | 8.8 | 0.02 | Jun 3, 2021 | A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2;… | ||
| CVE-2015-1877 | Hig | 0.57 | 8.8 | 0.03 | Jun 2, 2021 | The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file. | ||
| CVE-2021-29300 | Cri | 0.57 | 9.8 | 0.05 | May 24, 2021 | The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input. | ||
| CVE-2021-32090 | Cri | 0.57 | 9.8 | 0.02 | May 7, 2021 | The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter. | ||
| CVE-2020-13664 | Hig | 0.57 | 8.8 | 0.03 | May 5, 2021 | Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker… | ||
| CVE-2021-29369 | Cri | 0.57 | 9.8 | 0.02 | May 3, 2021 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | ||
| CVE-2021-22864 | Hig | 0.57 | 8.8 | 0.02 | Mar 23, 2021 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to override environment… | ||
| CVE-2020-10519 | Hig | 0.57 | 8.8 | 0.03 | Mar 3, 2021 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to… | ||
| CVE-2020-27862 | Hig | 0.57 | 8.8 | 0.01 | Feb 12, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on… | ||
| CVE-2021-27185 | Cri | 0.57 | 9.8 | 0.05 | Feb 10, 2021 | The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec. | ||
| CVE-2021-1299 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these… | ||
| CVE-2021-1298 | Hig | 0.57 | 8.8 | 0.02 | Jan 20, 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these… |
- risk 0.57cvss 9.8epss 0.04
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command…
- risk 0.57cvss 8.8epss 0.03
A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. An attacker could…
- risk 0.57cvss 8.8epss 0.02
Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order to find the right…
- risk 0.57cvss 9.8epss 0.04
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
- risk 0.57cvss 9.8epss 0.01
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two sequences and then inject arbitrary SMTP commands.
- risk 0.57cvss 8.8epss 0.02
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
- risk 0.57cvss 8.8epss 0.03
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
- risk 0.57cvss 8.8epss 0.03
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
- risk 0.57cvss 8.8epss 0.02
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2;…
- risk 0.57cvss 8.8epss 0.03
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
- risk 0.57cvss 9.8epss 0.05
The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.
- risk 0.57cvss 9.8epss 0.02
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.
- risk 0.57cvss 8.8epss 0.03
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker…
- risk 0.57cvss 9.8epss 0.02
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.
- risk 0.57cvss 8.8epss 0.02
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to override environment…
- risk 0.57cvss 8.8epss 0.03
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to…
- risk 0.57cvss 8.8epss 0.01
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on…
- risk 0.57cvss 9.8epss 0.05
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…
- risk 0.57cvss 8.8epss 0.02
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…