VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 94 of 192
  • CVE-2021-1262HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2021-1261HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2021-1260HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection attacks against an affected device, which could allow the attacker to take certain actions with root privileges on the device. For more information about these…

  • CVE-2020-4688HigJan 20, 2021
    risk 0.51cvss 7.8epss 0.01

    IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.

  • CVE-2018-19418HigJan 7, 2021
    risk 0.51cvss 7.8epss 0.08

    Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security permission control.

  • CVE-2019-14719HigOct 23, 2020
    risk 0.51cvss 7.8epss 0.01

    Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.

  • CVE-2020-9862HigOct 16, 2020
    risk 0.51cvss 7.8epss 0.02

    A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. Copying…

  • CVE-2020-0130HigSep 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2020-9688HigJul 17, 2020
    risk 0.51cvss 7.8epss 0.05

    Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-16011HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2019-20655HigApr 15, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 and XR700 before 1.0.1.20.

  • CVE-2020-3266HigMar 19, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability…

  • CVE-2020-1980HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later…

  • CVE-2019-17148HigJan 7, 2020
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this…

  • CVE-2019-9254HigSep 5, 2019
    risk 0.51cvss 7.8epss 0.00

    In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2017-18400HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.01

    cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).

  • CVE-2019-1893HigJul 6, 2019
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient input validation of…

  • CVE-2018-19450HigJun 17, 2019
    risk 0.51cvss 7.8epss 0.02

    A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) 5.4.0.1031 when parsing a launch action. An attacker can leverage this to gain remote code execution.

  • CVE-2018-19445HigJun 17, 2019
    risk 0.51cvss 7.8epss 0.03

    A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API app.launchURL is used. An attacker can leverage this to gain remote code execution.

  • CVE-2018-19451HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.03

    A command injection can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when using the Open File action on a Field. An attacker can leverage this to gain remote code execution.