VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 149 of 329
  • CVE-2021-26704HigMar 1, 2021
    risk 0.57cvss 8.8epss 0.03

    EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.

  • CVE-2021-20074HigFeb 16, 2021
    risk 0.57cvss 8.8epss 0.01

    Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

  • CVE-2021-27201HigFeb 15, 2021
    risk 0.57cvss 8.8epss 0.03

    Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.

  • CVE-2021-26752HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.01

    NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all…

  • CVE-2020-27861HigFeb 12, 2021
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Orbi 2.5.1.16 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UA_Parser utility. A crafted Host Name…

  • CVE-2021-27185CriFeb 10, 2021
    risk 0.57cvss 9.8epss 0.05

    The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.

  • CVE-2020-25036HigFeb 2, 2021
    risk 0.57cvss 8.8epss 0.02

    UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command.

  • CVE-2020-5626HigJan 28, 2021
    risk 0.57cvss 8.8epss 0.02

    Logstorage version 8.0.0 and earlier, and ELC Analytics version 3.0.0 and earlier allow remote attackers to execute arbitrary OS commands via a specially crafted log file.

  • CVE-2013-2512CriJan 26, 2021
    risk 0.57cvss 9.8epss 0.04

    The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.

  • CVE-2020-29017HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.04

    An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection vulnerability on the Customization page.

  • CVE-2020-35789HigDec 30, 2020
    risk 0.57cvss 8.8epss 0.03

    NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.

  • CVE-2020-25847HigDec 29, 2020
    risk 0.57cvss 8.8epss 0.03

    This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.

  • CVE-2020-35715HigDec 26, 2020
    risk 0.57cvss 8.8epss 0.04

    Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shell metacharacters in a filename to the upload_settings.cgi page.

  • CVE-2020-35714HigDec 26, 2020
    risk 0.57cvss 8.8epss 0.03

    Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via goform/systemCommand?command= in conjunction with the goform/pingstart program.

  • CVE-2020-25618HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs…

  • CVE-2020-25759HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.

  • CVE-2020-25757HigDec 15, 2020
    risk 0.57cvss 8.8epss 0.02

    A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with…

  • CVE-2020-5635HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.

  • CVE-2020-24297HigNov 18, 2020
    risk 0.57cvss 8.8epss 0.04

    httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST requests to the endpoint /admin/powerline. Fixed version: TL-WPA4220(EU)_V4_201023

  • CVE-2020-8273HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.