VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 143 of 329
  • CVE-2022-41642CriDec 5, 2022
    risk 0.57cvss 9.8epss 0.02

    OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

  • CVE-2022-45045HigDec 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and…

  • CVE-2022-40189CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2022-38649CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2022-40127HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.86

    A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

  • CVE-2022-44019HigOct 30, 2022
    risk 0.57cvss 8.8epss 0.02

    In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host parameter.

  • CVE-2022-35132HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.03

    Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.

  • CVE-2022-34427HigOct 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.

  • CVE-2022-40785HigSep 26, 2022
    risk 0.57cvss 8.8epss 0.02

    Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.

  • CVE-2022-39819HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.

  • CVE-2022-38094HigSep 8, 2022
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in the telnet function of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS command.

  • CVE-2022-35273HigSep 8, 2022
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in GUI setting page of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote authenticated attacker to execute an arbitrary OS command.

  • CVE-2022-38531HigSep 8, 2022
    risk 0.57cvss 8.8epss 0.02

    FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.

  • CVE-2022-30078HigSep 7, 2022
    risk 0.57cvss 8.8epss 0.02

    NETGEAR R6200_V2 firmware versions through R6200v2-V1.0.3.12_10.1.11 and R6300_V2 firmware versions through R6300v2-V1.0.4.52_10.0.93 allow remote authenticated attackers to execute arbitrary command via shell metacharacters in the ipv6_fix.cgi ipv6_wan_ipaddr, ipv6_lan_ipaddr,…

  • CVE-2022-37123HigAug 31, 2022
    risk 0.57cvss 8.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.

  • CVE-2022-34374HigAug 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

  • CVE-2022-36633HigAug 24, 2022
    risk 0.57cvss 8.8epss 0.49

    Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ssh agent installation link by URL encoding a bash escape with carriage return line feed. This url encoded payload can be used in place of a token and sent to a…

  • CVE-2022-25168CriAug 4, 2022
    risk 0.57cvss 9.8epss 0.04

    Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It…

  • CVE-2022-34540HigJul 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.

  • CVE-2022-34539HigJul 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.