VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 155 of 329
  • CVE-2019-13640CriJul 17, 2019
    risk 0.57cvss 9.8epss 0.08

    In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name…

  • CVE-2019-1576HigJul 16, 2019
    risk 0.57cvss 8.8epss 0.02

    Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run with the escalated user’s permissions.

  • CVE-2019-13155HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the IP Address in Add Virtual Server.

  • CVE-2019-13154HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the TCP Ports To Open in Add Gaming Rule.

  • CVE-2019-13153HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the Private Port in Add Virtual Server.

  • CVE-2019-13151HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the action set_sta_enrollee_pin_5g and the key wps_sta_enrollee_pin.

  • CVE-2019-13149HigJul 2, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the key passwd in Routing RIP Settings.

  • CVE-2019-12997HigJun 28, 2019
    risk 0.57cvss 8.8epss 0.02

    In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment (aka injection in the DEFAULT_SCORE_HOST environment variable).

  • CVE-2018-16593HigJun 19, 2019
    risk 0.57cvss 8.8epss 0.01

    The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.

  • CVE-2019-12787HigJun 10, 2019
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the Gateway key.

  • CVE-2018-10699HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functionality allows an attacker to execute…

  • CVE-2018-10697HigJun 7, 2019
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the…

  • CVE-2019-6738HigJun 3, 2019
    risk 0.57cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2019-6736HigJun 3, 2019
    risk 0.57cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay 23.0.10.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2018-16217HigMay 29, 2019
    risk 0.57cvss 8.8epss 0.03

    The network diagnostic function (ping) in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) allows a remote authenticated attacker to trigger OS commands or open a reverse shell via command injection.

  • CVE-2019-5425HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.02

    In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the SSH interface bypassing the CLI interface, which allow them to escalate privileges to root.

  • CVE-2019-5424HigApr 10, 2019
    risk 0.57cvss 8.8epss 0.02

    In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH CLI interface. This allows to execute shell commands under the root user.

  • CVE-2019-10631HigApr 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated attacker to execute arbitrary code via multiple different requests.

  • CVE-2019-9193HigApr 1, 2019
    risk 0.57cvss 7.2epss 0.92

    In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. This functionality is enabled by default and can be abused…

  • CVE-2019-10660HigMar 30, 2019
    risk 0.57cvss 8.8epss 0.03

    Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the /goform/systemlog?cmd=set logserver field.