VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 144 of 329
  • CVE-2022-34538HigJul 19, 2022
    risk 0.57cvss 8.8epss 0.03

    Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.

  • CVE-2022-27373HigJul 19, 2022
    risk 0.57cvss 8.8epss 0.04

    Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command execution (RCE) vulnerability via the Ping function.

  • CVE-2022-26481HigJul 17, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.

  • CVE-2022-28374HigJul 14, 2022
    risk 0.57cvss 8.8epss 0.02

    Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DMACC URLs on the Settings page of the Engineering portal. An authenticated remote attacker on the local network can inject shell metacharacters into…

  • CVE-2022-33948HigJul 4, 2022
    risk 0.57cvss 8.8epss 0.01

    HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

  • CVE-2014-0156CriJun 30, 2022
    risk 0.57cvss 9.8epss 0.03

    Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.

  • CVE-2022-32534HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.

  • CVE-2022-33140HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.04

    The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is…

  • CVE-2021-41738HigJun 11, 2022
    risk 0.57cvss 8.8epss 0.02

    ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

  • CVE-2022-1986CriJun 9, 2022
    risk 0.57cvss 9.8epss 0.04

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2022-31486HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware…

  • CVE-2021-34081HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.04

    OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.

  • CVE-2022-24394HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…

  • CVE-2022-24393HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…

  • CVE-2022-24392HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…

  • CVE-2022-24390HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The…

  • CVE-2022-24389HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is…

  • CVE-2022-24388HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is…

  • CVE-2021-42969HigMay 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

  • CVE-2022-27903HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.03

    An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.