VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 132 of 329
  • CVE-2024-39091HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.

  • CVE-2024-21879HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and <…

  • CVE-2024-24623HigJul 25, 2024
    risk 0.57cvss 8.8epss 0.02

    Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system.

  • CVE-2024-24622HigJul 25, 2024
    risk 0.57cvss 8.8epss 0.02

    Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system.

  • CVE-2024-31977HigJul 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

  • CVE-2024-36475HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.01

    FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.

  • CVE-2024-3798HigJul 10, 2024
    risk 0.57cvss epss 0.00

    Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local…

  • CVE-2024-39202HigJul 8, 2024
    risk 0.57cvss 8.8epss 0.01

    D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.

  • CVE-2024-37140HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS…

  • CVE-2024-4748HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server.  The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the project running on their computer might…

  • CVE-2024-37626HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.01

    A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.

  • CVE-2024-30368HigJun 6, 2024
    risk 0.57cvss 8.8epss 0.03

    A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-5421HigJun 4, 2024
    risk 0.57cvss epss 0.04

    Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

  • CVE-2024-5400HigMay 27, 2024
    risk 0.57cvss 8.8epss 0.01

    Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

  • CVE-2024-5297HigMay 23, 2024
    risk 0.57cvss 8.8epss 0.02

    D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Although authentication is required to exploit this vulnerability, the existing…

  • CVE-2024-5295HigMay 23, 2024
    risk 0.57cvss 8.8epss 0.02

    D-Link G416 flupl self Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 wireless routers. Authentication is not required to exploit this vulnerability. …

  • CVE-2024-5291HigMay 23, 2024
    risk 0.57cvss 8.8epss 0.02

    D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this…

  • CVE-2024-32351HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.

  • CVE-2022-43654HigMay 7, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The…

  • CVE-2024-33434CriMay 7, 2024
    risk 0.57cvss 9.8epss 0.01

    An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any…