VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 159 of 329
  • CVE-2017-14118HigSep 3, 2017
    risk 0.57cvss 8.8epss 0.02

    In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in the host_list parameter to module/tool_all/select_tool.php.

  • CVE-2017-11366CriAug 21, 2017
    risk 0.57cvss 9.8epss 0.08

    components/filemanager/class.filemanager.php in Codiad before 2.8.4 is vulnerable to remote command execution because shell commands can be embedded in parameter values, as demonstrated by search_file_type.

  • CVE-2017-2281HigAug 2, 2017
    risk 0.57cvss 8.8epss 0.01

    WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

  • CVE-2017-1318HigJul 18, 2017
    risk 0.57cvss 8.8epss 0.03

    IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.

  • CVE-2017-2185HigJul 7, 2017
    risk 0.57cvss 8.8epss 0.01

    HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.

  • CVE-2017-6712HigJul 6, 2017
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system can run certain shell…

  • CVE-2017-2850HigJun 29, 2017
    risk 0.57cvss 8.8epss 0.02

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing…

  • CVE-2017-2844HigJun 29, 2017
    risk 0.57cvss 8.8epss 0.03

    In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an…

  • CVE-2017-2843HigJun 27, 2017
    risk 0.57cvss 8.8epss 0.03

    In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an…

  • CVE-2017-2842HigJun 27, 2017
    risk 0.57cvss 8.8epss 0.03

    In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an…

  • CVE-2017-6682HigJun 13, 2017
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76).

  • CVE-2017-2128HigApr 28, 2017
    risk 0.57cvss 8.8epss 0.02

    Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data.

  • CVE-2017-2112HigApr 28, 2017
    risk 0.57cvss 8.8epss 0.02

    TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware…

  • CVE-2016-1468HigAug 8, 2016
    risk 0.57cvss 8.8epss 0.03

    The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.

  • CVE-2016-1297HigFeb 26, 2016
    risk 0.57cvss 8.8epss 0.03

    The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID…

  • CVE-2025-30241HigAug 10, 2026
    risk 0.56cvss epss 0.01

    Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions.  An authenticated adjacent attacker may inject specially crafted input to execute…

  • CVE-2026-56389HigJul 29, 2026
    risk 0.56cvss 8.6epss 0.00

    GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc,…

  • CVE-2026-12104HigJun 19, 2026
    risk 0.56cvss epss 0.01

    OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values…

  • CVE-2026-21267HigJan 13, 2026
    risk 0.56cvss 8.6epss 0.01

    Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue requires user…

  • CVE-2025-64091HigJan 9, 2026
    risk 0.56cvss 8.6epss 0.00

    This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.