VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,834)

page 70 of 192
  • CVE-2021-42740CriOct 21, 2021
    risk 0.57cvss 9.8epss 0.04

    The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real shell as a quoted argument to a command…

  • CVE-2021-34748HigOct 6, 2021
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficient input validation. An attacker could…

  • CVE-2021-36162HigSep 7, 2021
    risk 0.57cvss 8.8epss 0.02

    Apache Dubbo supports various rules to support configuration override or traffic routing (called routing in Dubbo). These rules are loaded into the configuration center (eg: Zookeeper, Nacos, ...) and retrieved by the customers when making a request in order to find the right…

  • CVE-2020-19001CriAug 27, 2021
    risk 0.57cvss 9.8epss 0.04

    Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.

  • CVE-2021-38189CriAug 8, 2021
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two sequences and then inject arbitrary SMTP commands.

  • CVE-2021-38169HigAug 7, 2021
    risk 0.57cvss 8.8epss 0.02

    Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

  • CVE-2020-17759HigJun 24, 2021
    risk 0.57cvss 8.8epss 0.03

    An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.

  • CVE-2020-21785HigJun 24, 2021
    risk 0.57cvss 8.8epss 0.03

    In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.

  • CVE-2021-28812HigJun 3, 2021
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2;…

  • CVE-2015-1877HigJun 2, 2021
    risk 0.57cvss 8.8epss 0.03

    The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.

  • CVE-2021-29300CriMay 24, 2021
    risk 0.57cvss 9.8epss 0.05

    The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.

  • CVE-2021-32090CriMay 7, 2021
    risk 0.57cvss 9.8epss 0.02

    The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.

  • CVE-2020-13664HigMay 5, 2021
    risk 0.57cvss 8.8epss 0.03

    Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on the file system. With this directory in place, an attacker…

  • CVE-2021-29369CriMay 3, 2021
    risk 0.57cvss 9.8epss 0.02

    The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.

  • CVE-2021-22864HigMar 23, 2021
    risk 0.57cvss 8.8epss 0.02

    A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to override environment…

  • CVE-2020-10519HigMar 3, 2021
    risk 0.57cvss 8.8epss 0.03

    A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to…

  • CVE-2020-27862HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.01

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dhttpd service, which listens on…

  • CVE-2021-27185CriFeb 10, 2021
    risk 0.57cvss 9.8epss 0.05

    The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.

  • CVE-2021-1299HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2021-1298HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…