VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,529)

page 109 of 327
  • CVE-2018-11160HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46).

  • CVE-2018-11159HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46).

  • CVE-2018-11158HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46).

  • CVE-2018-11157HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46).

  • CVE-2018-11156HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46).

  • CVE-2018-11155HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).

  • CVE-2018-11154HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).

  • CVE-2018-11153HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).

  • CVE-2018-11152HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).

  • CVE-2018-11150HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).

  • CVE-2018-11149HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).

  • CVE-2018-11148HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).

  • CVE-2018-11147HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).

  • CVE-2018-11146HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).

  • CVE-2018-11145HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).

  • CVE-2018-11144HigJun 2, 2018
    risk 0.58cvss 8.8epss 0.05

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).

  • CVE-2018-10354HigMay 23, 2018
    risk 0.58cvss 8.8epss 0.13

    A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this…

  • CVE-2018-10967HigMay 18, 2018
    risk 0.58cvss 8.8epss 0.04

    On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

  • CVE-2018-0279HigMay 17, 2018
    risk 0.58cvss 8.8epss 0.05

    A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to…

  • CVE-2017-14434HigMay 14, 2018
    risk 0.58cvss 8.8epss 0.04

    An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0=…