VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 205 of 329
  • CVE-2023-3261HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted…

  • CVE-2023-34254HigJun 23, 2023
    risk 0.49cvss 7.6epss 0.01

    The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific workflow the agent would run with the…

  • CVE-2023-35174HigJun 22, 2023
    risk 0.49cvss 8.6epss 0.01

    Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any user using Livebook Desktop…

  • CVE-2023-33381HigJun 6, 2023
    risk 0.49cvss 7.2epss 0.22

    A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending specially crafted input to the router via…

  • CVE-2023-20117HigApr 5, 2023
    risk 0.49cvss 7.2epss 0.28

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.…

  • CVE-2023-20128HigApr 5, 2023
    risk 0.49cvss 7.2epss 0.30

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.…

  • CVE-2023-28726HigMar 31, 2023
    risk 0.49cvss 7.5epss 0.01

    Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.

  • CVE-2023-0861HigFeb 16, 2023
    risk 0.49cvss 7.2epss 0.29

    NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119,…

  • CVE-2022-43758HigFeb 7, 2023
    risk 0.49cvss 7.6epss 0.01

    A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users…

  • CVE-2022-48069HigJan 27, 2023
    risk 0.49cvss 7.5epss 0.01

    Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.

  • CVE-2022-45461HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.

  • CVE-2022-42999HigOct 26, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

  • CVE-2020-7677HigJul 25, 2022
    risk 0.49cvss 8.6epss 0.02

    This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

  • CVE-2022-26482HigJul 17, 2022
    risk 0.49cvss 7.2epss 0.23

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

  • CVE-2021-44080HigJun 2, 2022
    risk 0.49cvss 7.2epss 0.25

    A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged in administrators to arbitrary OS commands as root in the device via the connection_type parameter of the statussupport_diagnostic_tracing.json endpoint.

  • CVE-2022-21143HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands.

  • CVE-2021-40412HigJan 28, 2022
    risk 0.49cvss 7.2epss 0.27

    An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead…

  • CVE-2021-40410HigJan 28, 2022
    risk 0.49cvss 7.2epss 0.28

    An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the value of the dns1 parameter provided through the SetLocal API, is not validated properly. This…

  • CVE-2021-30358HigOct 19, 2021
    risk 0.49cvss 7.2epss 0.27

    Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.

  • CVE-2021-1594HigOct 6, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a command injection attack and elevate privileges to root. This vulnerability is due to insufficient input validation for specific API endpoints. An…