VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 152 of 329
  • CVE-2020-7640CriApr 27, 2020
    risk 0.57cvss 9.8epss 0.02

    pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.

  • CVE-2018-21130HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2018-21127HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2018-21126HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2020-9478HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems.

  • CVE-2020-10603HigApr 9, 2020
    risk 0.57cvss 8.8epss 0.01

    WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.

  • CVE-2020-7634CriApr 6, 2020
    risk 0.57cvss 9.8epss 0.03

    heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

  • CVE-2020-7623CriApr 2, 2020
    risk 0.57cvss 9.8epss 0.04

    jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

  • CVE-2019-12123HigMar 18, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2019-12113HigMar 18, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2020-9436HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.03

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated…

  • CVE-2019-10807CriMar 11, 2020
    risk 0.57cvss 9.8epss 0.02

    Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.

  • CVE-2019-9859HigMar 10, 2020
    risk 0.57cvss 8.8epss 0.03

    Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result in remote root access on the server. The platform works with PHP as the frontend language and uses shell scripts to execute system actions. PHP executes shell…

  • CVE-2020-2159HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.

  • CVE-2019-17642HigMar 5, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharacters in a POST to centreon-autodiscovery-server/views/scan/ajax/call.php in the Autodiscovery plugin.

  • CVE-2020-5535HigMar 4, 2020
    risk 0.57cvss 8.8epss 0.01

    OpenBlocks IoT VX2 prior to Ver.4.0.0 (Ver.3 Series) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.

  • CVE-2019-10802CriFeb 28, 2020
    risk 0.57cvss 9.8epss 0.02

    giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.

  • CVE-2019-5140HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the…

  • CVE-2020-5524HigFeb 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via UPnP function.

  • CVE-2019-10791CriFeb 18, 2020
    risk 0.57cvss 9.8epss 0.02

    promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.