VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 13 of 324
  • CVE-2023-35138CriNov 30, 2023
    risk 0.67cvss 9.8epss 0.40

    A command injection vulnerability in the “show_zysync_server_contents” function of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by…

  • CVE-2023-34127HigJul 13, 2023
    risk 0.67cvss 8.8epss 0.86

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier…

  • CVE-2023-30253HigMay 29, 2023
    risk 0.67cvss 8.8epss 0.79

    Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

  • CVE-2022-46476CriJan 19, 2023
    risk 0.67cvss 9.8epss 0.41

    D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.

  • CVE-2022-29337CriMay 24, 2022
    risk 0.67cvss 9.8epss 0.35

    C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2022-25064CriFeb 25, 2022
    risk 0.67cvss 9.8epss 0.36

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

  • CVE-2021-21881CriDec 22, 2021
    risk 0.67cvss 9.9epss 0.36

    An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2020-29390CriNov 30, 2020
    risk 0.67cvss 9.8epss 0.40

    Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

  • CVE-2020-17505HigAug 12, 2020
    risk 0.67cvss 8.8epss 0.82

    Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.

  • CVE-2020-13851HigJun 11, 2020
    risk 0.67cvss 8.8epss 0.91

    Artica Pandora FMS 7.44 allows remote command execution via the events feature.

  • CVE-2020-8605HigMay 27, 2020
    risk 0.67cvss 8.8epss 0.88

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

  • CVE-2016-11021HigKEVMar 9, 2020
    risk 0.67cvss 7.2epss 0.69

    setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

  • CVE-2020-8654HigFeb 7, 2020
    risk 0.67cvss 8.8epss 0.86

    An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module/module_frame/index.php autodiscovery.php target field.

  • CVE-2020-5505CriJan 14, 2020
    risk 0.67cvss 9.8epss 0.44

    Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.

  • CVE-2012-5878CriJan 3, 2020
    risk 0.67cvss 9.8epss 0.09

    Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to…

  • CVE-2019-5129CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.39

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-5127CriOct 25, 2019
    risk 0.67cvss 9.8epss 0.45

    A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The…

  • CVE-2019-18370CriOct 23, 2019
    risk 0.67cvss 9.8epss 0.40

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the…

  • CVE-2019-12988CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.43

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

  • CVE-2019-12987CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.43

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).