VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 138 of 329
  • CVE-2023-40582CriAug 30, 2023
    risk 0.57cvss 9.8epss 0.01

    find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the…

  • CVE-2023-1997HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

  • CVE-2023-37249HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.

  • CVE-2023-40144HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H,…

  • CVE-2023-40072HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request.

  • CVE-2023-39944HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request.

  • CVE-2023-39455HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-600GHBK-A all versions, WRC-1467GHBK-A all versions,…

  • CVE-2023-34213HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentially allow malicious users to execute…

  • CVE-2023-33239HigAug 17, 2023
    risk 0.57cvss 8.8epss 0.01

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow…

  • CVE-2023-33013HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.02

    A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.

  • CVE-2023-40267CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

  • CVE-2023-31209HigAug 10, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.

  • CVE-2022-48604HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48603HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48602HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48601HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48600HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48599HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48598HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…

  • CVE-2022-48597HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.