VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 73 of 192
  • CVE-2019-12786HigJun 10, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.

  • CVE-2019-10854HigMay 23, 2019
    risk 0.57cvss 8.8epss 0.03

    Computrols CBAS 18.0.0 allows Authenticated Command Injection.

  • CVE-2018-7826HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.02

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen Pelco Sarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

  • CVE-2018-7825HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.02

    A Command Injection vulnerability exists in the web-based GUI of the 1st Gen PelcoSarix Enhanced Camera that could allow a remote attacker to execute arbitrary commands.

  • CVE-2019-5424HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.02

    In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.

  • CVE-2019-9743HigMar 26, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on PHOENIX CONTACT RAD-80211-XD and RAD-80211-XD/HP-BUS devices. Command injection can occur in the WebHMI component.

  • CVE-2019-7537CriMar 21, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can execute arbitrary Python commands, resulting in command execution.

  • CVE-2018-14893HigNov 27, 2018
    risk 0.57cvss 8.8epss 0.03

    A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API.

  • CVE-2018-0454HigOct 5, 2018
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform command injection. The vulnerability is due to insufficient input validation of command input. An attacker could exploit this…

  • CVE-2018-15356HigAug 17, 2018
    risk 0.57cvss 8.8epss 0.03

    An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0.

  • CVE-2018-3772CriJul 30, 2018
    risk 0.57cvss 9.8epss 0.03

    Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary commands. The `whereis` module is deprecated and it is recommended to use the `which` npm module instead.

  • CVE-2018-0350HigJul 18, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit…

  • CVE-2018-1244HigJul 2, 2018
    risk 0.57cvss 8.8epss 0.03

    Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration privileges could potentially exploit this vulnerability to…

  • CVE-2018-5428HigJun 20, 2018
    risk 0.57cvss 8.8epss 0.03

    The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data Virtualization: 7.0.5; 7.0.6.

  • CVE-2017-16100CriJun 7, 2018
    risk 0.57cvss 9.8epss 0.05

    dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

  • CVE-2018-3746CriJun 1, 2018
    risk 0.57cvss 9.8epss 0.05

    The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.

  • CVE-2017-7161HigApr 3, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection.

  • CVE-2016-0324HigJan 12, 2018
    risk 0.57cvss 8.8epss 0.04

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640.

  • CVE-2017-8135HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…

  • CVE-2017-8134HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…