VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 170 of 329
  • CVE-2021-3708HigAug 16, 2021
    risk 0.53cvss 7.8epss 0.25

    D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.

  • CVE-2021-1602HigAug 4, 2021
    risk 0.53cvss 8.2epss 0.02

    A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This…

  • CVE-2021-23412HigJul 23, 2021
    risk 0.53cvss 8.1epss 0.04

    All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

  • CVE-2021-28800HigJun 24, 2021
    risk 0.53cvss 8.1epss 0.01

    A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to…

  • CVE-2021-23012HigMay 10, 2021
    risk 0.53cvss 8.2epss 0.00

    On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administrator" or "Administrator" roles to…

  • CVE-2021-0265HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.03

    An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on the host running the AppFormix Agent, when certain preconditions are performed by the attacker, thus granting the attacker full…

  • CVE-2020-28429HigFeb 23, 2021
    risk 0.53cvss 7.3epss 0.63

    All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

  • CVE-2021-21016CriFeb 11, 2021
    risk 0.53cvss 9.1epss 0.05

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin console is required for…

  • CVE-2020-35851HigDec 31, 2020
    risk 0.53cvss 8.1epss 0.02

    HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.

  • CVE-2020-10209HigDec 30, 2020
    risk 0.53cvss 8.1epss 0.03

    Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-the-middle attackers to execute arbitrary commands with root level privileges.

  • CVE-2020-24581HigDec 22, 2020
    risk 0.53cvss 8.0epss 0.14

    An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.

  • CVE-2020-12774HigJul 22, 2020
    risk 0.53cvss 8.2epss 0.00

    D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.

  • CVE-2020-2034HigJul 8, 2020
    risk 0.53cvss 8.1epss 0.07

    An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit this issue. This issue can not be…

  • CVE-2020-11581HigApr 6, 2020
    risk 0.53cvss 8.1epss 0.10

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks…

  • CVE-2019-11689HigMar 18, 2020
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execution as root.

  • CVE-2020-1931HigJan 30, 2020
    risk 0.53cvss 8.1epss 0.06

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts to exploit the issue will throw warnings.…

  • CVE-2020-1930HigJan 30, 2020
    risk 0.53cvss 8.1epss 0.07

    A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can be injected in a number of scenarios…

  • CVE-2019-17095HigJan 27, 2020
    risk 0.53cvss 8.1epss 0.04

    A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of…

  • CVE-2019-15978HigJan 6, 2020
    risk 0.53cvss 7.2epss 0.37

    Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on the underlying operating system (OS). For…

  • CVE-2018-16118HigJun 20, 2019
    risk 0.53cvss 8.1epss 0.04

    A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.