VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 201 of 329
  • CVE-2024-0815HigMar 7, 2024
    risk 0.50cvss 8.8epss 0.01

    Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

  • CVE-2023-47415HigMar 7, 2024
    risk 0.50cvss 7.5epss 0.14

    Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

  • CVE-2023-24422HigJan 26, 2023
    risk 0.50cvss 8.8epss 0.01

    A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in…

  • CVE-2022-39321HigOct 25, 2022
    risk 0.50cvss 8.8epss 0.02

    GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the docker cli directly in order to run job containers, service containers, or container actions. A bug in the logic for how the environment is encoded into these…

  • CVE-2021-34078HigJun 2, 2022
    risk 0.50cvss 8.8epss 0.03

    lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.

  • CVE-2022-24881HigApr 26, 2022
    risk 0.50cvss 8.8epss 0.03

    Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates…

  • CVE-2022-25175HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

  • CVE-2022-25174HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM…

  • CVE-2022-25173HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the…

  • CVE-2021-31854HigJan 19, 2022
    risk 0.50cvss 7.7epss 0.01

    A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment…

  • CVE-2022-20617HigJan 12, 2022
    risk 0.50cvss 8.8epss 0.02

    Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM…

  • CVE-2020-19316HigDec 20, 2021
    risk 0.50cvss 8.8epss 0.03

    OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

  • CVE-2021-37708HigAug 16, 2021
    risk 0.50cvss 8.8epss 0.02

    Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available…

  • CVE-2021-32673HigJun 8, 2021
    risk 0.50cvss 8.8epss 0.02

    reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade to version 0.10.16 or later to resolve…

  • CVE-2020-26284HigDec 21, 2020
    risk 0.50cvss 7.7epss 0.01

    Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%PATH%` on Windows. In Hugo before version 0.79.1, if a malicious file with the…

  • CVE-2020-28581HigNov 18, 2020
    risk 0.50cvss 7.2epss 0.45

    A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

  • CVE-2020-28580HigNov 18, 2020
    risk 0.50cvss 7.2epss 0.45

    A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary OS commands with elevated privileges.

  • CVE-2020-14144HigOct 16, 2020
    risk 0.50cvss 7.2epss 0.95

    The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., one viewpoint is that the dangerousness of this feature should be documented immediately above the…

  • CVE-2020-10235HigMar 9, 2020
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Froxlor before 0.10.14. Remote attackers with access to the installation routine could have executed arbitrary code via the database configuration options that were passed unescaped to exec, because of _backupExistingDatabase in…

  • CVE-2020-7597HigFeb 17, 2020
    risk 0.50cvss 8.8epss 0.03

    codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.