VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 12 of 324
  • CVE-2018-20218CriMar 21, 2019
    risk 0.68cvss 9.8epss 0.11

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the…

  • CVE-2018-18322CriOct 15, 2018
    risk 0.68cvss 9.8epss 0.15

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.

  • CVE-2018-12465CriJun 29, 2018
    risk 0.68cvss 9.1epss 0.79

    An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with…

  • CVE-2018-1143CriApr 19, 2018
    risk 0.68cvss 9.8epss 0.55

    A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to twonky_command.cgi.

  • CVE-2018-6911CriFeb 13, 2018
    risk 0.68cvss 9.8epss 0.13

    The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).

  • CVE-2017-14094CriJan 19, 2018
    risk 0.68cvss 9.8epss 0.19

    A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.

  • CVE-2014-8389CriDec 28, 2017
    risk 0.68cvss 9.8epss 0.51

    cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware…

  • CVE-2017-16934CriNov 24, 2017
    risk 0.68cvss 9.8epss 0.13

    The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp…

  • CVE-2015-2279CriJul 25, 2017
    risk 0.68cvss 9.8epss 0.18

    cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac write_pid, write_msn, write_tan, or…

  • CVE-2017-7175CriJul 10, 2017
    risk 0.68cvss 9.9epss 0.07

    NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).

  • CVE-2017-3506HigKEVApr 24, 2017
    risk 0.68cvss 7.4epss 0.96

    Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with…

  • CVE-2017-8051CriApr 21, 2017
    risk 0.68cvss 9.8epss 0.16

    Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.

  • CVE-2017-6182CriMar 30, 2017
    risk 0.68cvss 9.8epss 0.17

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.

  • CVE-2026-28517CriFeb 27, 2026
    risk 0.67cvss 9.8epss 0.06

    openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.php. The application retrieves the 'dot' configuration parameter from the database and passes it directly to exec() without validation or sanitization. If an…

  • CVE-2025-64155CriJan 13, 2026
    risk 0.67cvss 9.8epss 0.43

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an…

  • CVE-2021-47667CriApr 5, 2025
    risk 0.67cvss 10.0epss 0.33

    An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

  • CVE-2024-53584CriJan 31, 2025
    risk 0.67cvss 9.8epss 0.04

    OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

  • CVE-2024-12987HigKEVDec 27, 2024
    risk 0.67cvss 7.3epss 0.98

    A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads…

  • CVE-2023-51572CriApr 1, 2024
    risk 0.67cvss 9.8epss 0.38

    Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this…

  • CVE-2023-4473CriNov 30, 2023
    risk 0.67cvss 9.8epss 0.41

    A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable…