CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,529)
page 109 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11160 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46). | ||
| CVE-2018-11159 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46). | ||
| CVE-2018-11158 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46). | ||
| CVE-2018-11157 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46). | ||
| CVE-2018-11156 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46). | ||
| CVE-2018-11155 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46). | ||
| CVE-2018-11154 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46). | ||
| CVE-2018-11153 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46). | ||
| CVE-2018-11152 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46). | ||
| CVE-2018-11150 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46). | ||
| CVE-2018-11149 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46). | ||
| CVE-2018-11148 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46). | ||
| CVE-2018-11147 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46). | ||
| CVE-2018-11146 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46). | ||
| CVE-2018-11145 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46). | ||
| CVE-2018-11144 | Hig | 0.58 | 8.8 | 0.05 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46). | ||
| CVE-2018-10354 | Hig | 0.58 | 8.8 | 0.13 | May 23, 2018 | A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this… | ||
| CVE-2018-10967 | Hig | 0.58 | 8.8 | 0.04 | May 18, 2018 | On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution. | ||
| CVE-2018-0279 | Hig | 0.58 | 8.8 | 0.05 | May 17, 2018 | A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to… | ||
| CVE-2017-14434 | Hig | 0.58 | 8.8 | 0.04 | May 14, 2018 | An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0=… |
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).
- risk 0.58cvss 8.8epss 0.05
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).
- risk 0.58cvss 8.8epss 0.13
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this…
- risk 0.58cvss 8.8epss 0.04
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
- risk 0.58cvss 8.8epss 0.05
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system on the affected device. The vulnerability is due to…
- risk 0.58cvss 8.8epss 0.04
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0=…