VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 153 of 329
  • CVE-2020-8949HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.03

    Gocloud S2A_WL 4.2.7.16471, S2A 4.2.7.17278, S2A 4.3.0.15815, S2A 4.3.0.17193, S3A K2P MTK 4.2.7.16528, S3A 4.3.0.16572, and ISP3000 4.3.0.17190 devices allows remote attackers to execute arbitrary OS commands via shell metacharacters in a ping operation, as demonstrated by the…

  • CVE-2020-8946HigFeb 12, 2020
    risk 0.57cvss 8.8epss 0.02

    Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.

  • CVE-2020-8429HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    The Admin web application in Kinetica 7.0.9.2.20191118151947 does not properly sanitise the input for the function getLogs. This lack of sanitisation could be exploited to allow an authenticated attacker to run remote code on the underlying operating system. The logFile…

  • CVE-2013-4267CriFeb 11, 2020
    risk 0.57cvss 9.8epss 0.04

    Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the…

  • CVE-2019-10788CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.02

    im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

  • CVE-2019-10787CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.04

    im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

  • CVE-2020-7596HigJan 25, 2020
    risk 0.57cvss 8.8epss 0.02

    Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.

  • CVE-2012-4981HigJan 23, 2020
    risk 0.57cvss 8.8epss 0.03

    Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability

  • CVE-2019-10780CriJan 22, 2020
    risk 0.57cvss 9.8epss 0.03

    BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.

  • CVE-2020-7240HigJan 20, 2020
    risk 0.57cvss 8.8epss 0.02

    Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Configuration). Note: According to the description, the vulnerability requires a fully…

  • CVE-2020-1609HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute commands as root on the…

  • CVE-2020-1605HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute commands as root on the…

  • CVE-2020-6948CriJan 13, 2020
    risk 0.57cvss 9.8epss 0.03

    A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.

  • CVE-2020-6757HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.01

    contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.

  • CVE-2019-10778CriJan 8, 2020
    risk 0.57cvss 9.8epss 0.03

    devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.

  • CVE-2019-10776CriJan 7, 2020
    risk 0.57cvss 9.8epss 0.02

    In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

  • CVE-2019-5987HigJan 6, 2020
    risk 0.57cvss 8.8epss 0.03

    Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page.

  • CVE-2012-5693HigJan 3, 2020
    risk 0.57cvss 8.8epss 0.02

    Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in frameworkgui/; the filename parameter to (3) CSAttack.pl or…

  • CVE-2019-9197HigDec 31, 2019
    risk 0.57cvss 8.8epss 0.04

    The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.

  • CVE-2019-10774CriDec 30, 2019
    risk 0.57cvss 9.8epss 0.05

    php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.