VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 166 of 329
  • CVE-2021-33548HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.57

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-28571HigSep 8, 2021
    risk 0.54cvss 8.3epss 0.03

    Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution…

  • CVE-2021-36011HigAug 20, 2021
    risk 0.54cvss 8.3epss 0.02

    Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained with a development and debugging tool for JavaScript scripts. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution…

  • CVE-2021-21530HigApr 30, 2021
    risk 0.54cvss 8.3epss 0.01

    Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive…

  • CVE-2021-29465HigApr 22, 2021
    risk 0.54cvss 8.3epss 0.02

    Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is able to overwrite any file on the system with the command results. This can result in remote code execution when the user…

  • CVE-2021-21386CriMar 24, 2021
    risk 0.54cvss 9.3epss 0.02

    APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could include arguments that allow unintended…

  • CVE-2020-15271CriOct 26, 2020
    risk 0.54cvss 9.3epss 0.02

    In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is…

  • CVE-2020-15123CriJul 20, 2020
    risk 0.54cvss 9.3epss 0.04

    In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for…

  • CVE-2020-12242HigApr 27, 2020
    risk 0.54cvss 7.8epss 0.01

    Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.

  • CVE-2019-3999HigFeb 25, 2020
    risk 0.54cvss 7.8epss 0.09

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

  • CVE-2019-8513HigDec 18, 2019
    risk 0.54cvss 7.8epss 0.03

    This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.

  • CVE-2019-1636HigJan 23, 2019
    risk 0.54cvss 7.8epss 0.47

    A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating systems. An…

  • CVE-2018-18859HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18858HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18857HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18856HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-6222HigMar 15, 2018
    risk 0.54cvss 7.8epss 0.01

    Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

  • CVE-2017-7690HigApr 14, 2017
    risk 0.54cvss 7.8epss 0.01

    Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.

  • CVE-2015-6396HigAug 8, 2016
    risk 0.54cvss 7.8epss 0.02

    The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

  • CVE-2026-74801HigAug 17, 2026
    risk 0.53cvss 8.2epss 0.00

    SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft…