VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 151 of 329
  • CVE-2020-14414HigJun 29, 2020
    risk 0.57cvss 8.8epss 0.04

    NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a pw…

  • CVE-2020-14412HigJun 29, 2020
    risk 0.57cvss 8.8epss 0.04

    NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacters from a POST request. An attacker can exploit this by crafting an arbitrary payload (any system commands) that contains shell metacharacters via a POST request with a…

  • CVE-2020-9578CriJun 26, 2020
    risk 0.57cvss 9.8epss 0.06

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9576CriJun 26, 2020
    risk 0.57cvss 9.8epss 0.06

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-16213HigJun 25, 2020
    risk 0.57cvss 8.8epss 0.03

    Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter to inject and execute arbitrary…

  • CVE-2020-14950HigJun 21, 2020
    risk 0.57cvss 8.8epss 0.03

    aaPanel through 6.6.6 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a modified /system?action=ServiceAdmin request (start, stop, or restart) to the setting menu of Sotfware Store.

  • CVE-2020-14081HigJun 15, 2020
    risk 0.57cvss 8.8epss 0.02

    TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action send_log_email with the key auth_acname (or auth_passwd), allowing an authenticated user to run arbitrary commands on the device.

  • CVE-2020-14075HigJun 15, 2020
    risk 0.57cvss 8.8epss 0.03

    TRENDnet TEW-827DRU devices through 2.06B04 contain multiple command injections in apply.cgi via the action pppoe_connect, ru_pppoe_connect, or dhcp_connect with the key wan_ifname (or wan0_dns), allowing an authenticated user to run arbitrary commands on the device.

  • CVE-2020-13976HigJun 9, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report…

  • CVE-2020-3224HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to inject IOS commands to an affected device. The injected commands should require a higher privilege level in order to be…

  • CVE-2020-3205HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, adjacent attacker to execute…

  • CVE-2020-4180HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM Security Guardium 11.1 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 174735.

  • CVE-2020-2200HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoint, resulting in an OS command injection vulnerability exploitable by users able to store such a file on the Jenkins master.

  • CVE-2020-13694HigJun 1, 2020
    risk 0.57cvss 8.8epss 0.02

    In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.

  • CVE-2020-11950HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.03

    VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

  • CVE-2020-11766HigMay 19, 2020
    risk 0.57cvss 8.8epss 0.02

    sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.

  • CVE-2020-2014HigMay 13, 2020
    risk 0.57cvss 8.8epss 0.03

    An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions…

  • CVE-2020-6651HigMay 7, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper Input Validation in Eaton's Intelligent Power Manager (IPM) v 1.67 & prior on file name during configuration file import functionality allows attackers to perform command injection or code execution via specially crafted file names while uploading the configuration file…

  • CVE-2019-19220HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.02

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).

  • CVE-2019-19217HigApr 30, 2020
    risk 0.57cvss 8.8epss 0.02

    BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.