VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 206 of 329
  • CVE-2021-31605HigSep 27, 2021
    risk 0.49cvss 7.5epss 0.03

    furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.

  • CVE-2021-32751HigJul 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user…

  • CVE-2021-23359HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command…

  • CVE-2020-28494HigFeb 2, 2021
    risk 0.49cvss 8.6epss 0.02

    This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue occurs because child_process.spawn is called with the option…

  • CVE-2020-14293HigOct 2, 2020
    risk 0.49cvss 7.5epss 0.05

    conf_datetime in Secudos DOMOS 5.8 allows remote attackers to execute arbitrary commands as root via shell metacharacters in the zone field (obtained from the web interface).

  • CVE-2020-15778HigJul 24, 2020
    risk 0.49cvss 7.4epss 0.13

    scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that…

  • CVE-2019-1020004HigJul 29, 2019
    risk 0.49cvss 7.5epss 0.01

    Tridactyl before 1.16.0 allows fake key events.

  • CVE-2019-6962HigJun 20, 2019
    risk 0.49cvss 7.5epss 0.02

    A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login credentials to execute arbitrary shell commands under the CcspWifiSsp process (running as root) if the platform was compiled with the ENABLE_FEATURE_MESHWIFI…

  • CVE-2019-1878HigJun 20, 2019
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, adjacent attacker to inject arbitrary shell commands that are executed by the device. The…

  • CVE-2019-3914HigApr 11, 2019
    risk 0.49cvss 7.2epss 0.30

    Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname.

  • CVE-2018-13285HigApr 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

  • CVE-2018-13284HigApr 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.

  • CVE-2018-16090HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.01

    In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to post-authentication command injection.

  • CVE-2018-16089HigNov 27, 2018
    risk 0.49cvss 7.5epss 0.02

    In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insufficiently sanitized, allowing post-authentication command injection on the SMM as the root user.

  • CVE-2018-10987HigJul 5, 2018
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute commands on the vacuum cleaner as root. The…

  • CVE-2018-1238HigMar 27, 2018
    risk 0.49cvss 7.5epss 0.01

    Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for certain actions. A remote malicious user, with network access…

  • CVE-2016-0634HigAug 28, 2017
    risk 0.49cvss 7.5epss 0.06

    The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.

  • CVE-2017-7414HigApr 4, 2017
    risk 0.49cvss 7.5epss 0.01

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?"…

  • CVE-2016-6631HigDec 11, 2016
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is executed as a command-line argument by the…

  • CVE-2016-2876HigNov 30, 2016
    risk 0.49cvss 7.5epss 0.02

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.