VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 92 of 192
  • CVE-2024-23247HigMar 8, 2024
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2024-22545HigJan 26, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.

  • CVE-2023-50274HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.01

    HPE OneView may allow command injection with local privilege escalation.

  • CVE-2023-24135HigJan 22, 2024
    risk 0.51cvss 7.8epss 0.02

    Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary commands via manipulation of the mac parameter.

  • CVE-2023-42136HigJan 15, 2024
    risk 0.51cvss 7.8epss 0.00

    PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word. The attacker must have shell access to the device in order…

  • CVE-2023-4401HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.…

  • CVE-2023-40796HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.01

    Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

  • CVE-2023-32782HigAug 9, 2023
    risk 0.51cvss 7.2epss 0.56

    A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity…

  • CVE-2023-32781HigAug 9, 2023
    risk 0.51cvss 7.2epss 0.14

    A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The…

  • CVE-2023-35390HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.02

    .NET and Visual Studio Remote Code Execution Vulnerability

  • CVE-2023-33298HigJun 30, 2023
    risk 0.51cvss 7.8epss 0.01

    com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usingCAPath.

  • CVE-2023-24032HigJun 15, 2023
    risk 0.51cvss 7.8epss 0.01

    In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).

  • CVE-2023-33919HigJun 13, 2023
    risk 0.51cvss 7.2epss 0.48

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an…

  • CVE-2023-26294HigJun 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2022-25834HigJun 7, 2023
    risk 0.51cvss 7.8epss 0.00

    In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands.

  • CVE-2023-34153HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.03

    A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.

  • CVE-2023-26127HigMay 27, 2023
    risk 0.51cvss 7.8epss 0.01

    All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** To execute the code snippet and potentially exploit the vulnerability, the attacker needs to have the ability to run Node.js code…

  • CVE-2023-31742HigMay 22, 2023
    risk 0.51cvss 7.2epss 0.09

    There is a command injection vulnerability in the Linksys WRT54GL router with firmware version 4.30.18.006. If an attacker gains web management privileges, they can inject commands into the post request parameters wl_ant, wl_rate, WL_atten_ctl, ttcp_num, ttcp_size in the httpd s…

  • CVE-2023-32700HigMay 20, 2023
    risk 0.51cvss 7.8epss 0.01

    LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

  • CVE-2023-2491HigMay 17, 2023
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in…