CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,529)
page 105 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-3611 | Hig | 0.58 | 8.8 | 0.06 | Feb 4, 2020 | A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report. | ||
| CVE-2019-4715 | Hig | 0.58 | 8.8 | 0.04 | Dec 11, 2019 | IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093. | ||
| CVE-2019-19117 | Hig | 0.58 | 8.8 | 0.05 | Nov 18, 2019 | /usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter. | ||
| CVE-2013-2024 | Hig | 0.58 | 8.8 | 0.05 | Oct 31, 2019 | OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. | ||
| CVE-2019-15530 | Hig | 0.58 | 8.8 | 0.04 | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login. | ||
| CVE-2019-15529 | Hig | 0.58 | 8.8 | 0.08 | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login. | ||
| CVE-2019-15528 | Hig | 0.58 | 8.8 | 0.04 | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings. | ||
| CVE-2019-15527 | Hig | 0.58 | 8.8 | 0.04 | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings. | ||
| CVE-2019-15526 | Hig | 0.58 | 8.8 | 0.04 | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482. | ||
| CVE-2019-15060 | Hig | 0.58 | 8.8 | 0.04 | Aug 22, 2019 | The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field. | ||
| CVE-2019-3968 | Hig | 0.58 | 8.8 | 0.10 | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form. | ||
| CVE-2019-14923 | Hig | 0.58 | 8.8 | 0.04 | Aug 16, 2019 | EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field. | ||
| CVE-2019-12792 | Hig | 0.58 | 8.8 | 0.05 | Aug 15, 2019 | A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. | ||
| CVE-2019-13567 | Hig | 0.58 | 8.8 | 0.04 | Jul 12, 2019 | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute… | ||
| CVE-2019-13482 | Hig | 0.58 | 8.8 | 0.08 | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings. | ||
| CVE-2019-13481 | Hig | 0.58 | 8.8 | 0.08 | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings. | ||
| CVE-2019-13128 | Hig | 0.58 | 8.8 | 0.08 | Jul 1, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings. | ||
| CVE-2018-10702 | Hig | 0.58 | 8.8 | 0.05 | Jun 7, 2019 | An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter… | ||
| CVE-2019-6739 | Hig | 0.58 | 8.8 | 0.10 | Jun 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way… | ||
| CVE-2019-11224 | Hig | 0.58 | 8.8 | 0.07 | May 15, 2019 | HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. |
- risk 0.58cvss 8.8epss 0.06
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
- risk 0.58cvss 8.8epss 0.04
IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 172093.
- risk 0.58cvss 8.8epss 0.05
/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticated users to execute any command via shell metacharacters in the cgi-bin/luci autoUpTime parameter.
- risk 0.58cvss 8.8epss 0.05
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
- risk 0.58cvss 8.8epss 0.04
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the LoginPassword field to Login.
- risk 0.58cvss 8.8epss 0.08
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Username field to Login.
- risk 0.58cvss 8.8epss 0.04
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Interface field to SetStaticRouteSettings.
- risk 0.58cvss 8.8epss 0.04
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MaxIdTime field to SetWanSettings.
- risk 0.58cvss 8.8epss 0.04
An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings, a related issue to CVE-2019-13482.
- risk 0.58cvss 8.8epss 0.04
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
- risk 0.58cvss 8.8epss 0.10
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
- risk 0.58cvss 8.8epss 0.04
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
- risk 0.58cvss 8.8epss 0.05
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root.
- risk 0.58cvss 8.8epss 0.04
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute…
- risk 0.58cvss 8.8epss 0.08
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the Type field to SetWanSettings.
- risk 0.58cvss 8.8epss 0.08
An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the MTU field to SetWanSettings.
- risk 0.58cvss 8.8epss 0.08
An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploitable with Authentication) via shell metacharacters in the IPAddress or Gateway field to SetStaticRouteSettings.
- risk 0.58cvss 8.8epss 0.05
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on the device. The POST parameter…
- risk 0.58cvss 8.8epss 0.10
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way…
- risk 0.58cvss 8.8epss 0.07
HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.