VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 156 of 329
  • CVE-2019-10659HigMar 30, 2019
    risk 0.57cvss 8.8epss 0.03

    Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in a /manager?action=getlogcat priority field.

  • CVE-2019-10658HigMar 30, 2019
    risk 0.57cvss 8.8epss 0.03

    Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacharacters in the filename in a /ubus/controller.icc.update_nds_webroot_from_tmp update_nds_webroot_from_tmp API call.

  • CVE-2019-10061CriMar 26, 2019
    risk 0.57cvss 9.8epss 0.04

    utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.

  • CVE-2018-1998HigMar 11, 2019
    risk 0.57cvss 8.8epss 0.00

    IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM X-ForceID: 154887.

  • CVE-2018-15380HigFeb 20, 2019
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2019-1650HigJan 24, 2019
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected…

  • CVE-2018-17707HigJan 24, 2019
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

  • CVE-2018-16200HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.

  • CVE-2018-16195HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP.

  • CVE-2018-19907HigDec 6, 2018
    risk 0.57cvss 8.8epss 0.02

    A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl filetype) that triggers a call to freemarker.template.utility.Execute in the FreeMarker library…

  • CVE-2018-12317HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.03

    OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name" POST parameter.

  • CVE-2018-12316HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.03

    OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST parameter.

  • CVE-2018-12312HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.03

    OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL parameter.

  • CVE-2018-12307HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.03

    OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST parameter.

  • CVE-2018-14893HigNov 27, 2018
    risk 0.57cvss 8.8epss 0.03

    A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API.

  • CVE-2018-15710HigNov 14, 2018
    risk 0.57cvss 7.8epss 0.44

    Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

  • CVE-2018-0432HigOct 5, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the error…

  • CVE-2018-17208HigSep 19, 2018
    risk 0.57cvss 8.8epss 0.03

    Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access, via cgi-bin/zbtest.cgi or cgi-bin/zbtest2.cgi (scripts that can be discovered with binwalk on the firmware, but are not visible in the web interface). This…

  • CVE-2018-3952HigSep 7, 2018
    risk 0.57cvss 8.8epss 0.01

    An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can cause a privilege escalation, resulting in the execution of arbitrary commands with system privileges.

  • CVE-2018-16334HigSep 2, 2018
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST request is used directly in a doSystemCmd call, causing OS command injection.