CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,529)
page 212 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4542 | Med | 0.48 | 6.3 | 0.88 | Aug 25, 2023 | A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack… | ||
| CVE-2023-24261 | Hig | 0.48 | 7.2 | 0.19 | Jun 21, 2023 | A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request. | ||
| CVE-2023-26490 | Hig | 0.48 | 7.3 | 0.02 | Mar 4, 2023 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse… | ||
| CVE-2022-25855 | Hig | 0.48 | 7.4 | 0.01 | Feb 6, 2023 | All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization. | ||
| CVE-2022-25853 | Hig | 0.48 | 7.4 | 0.01 | Feb 6, 2023 | All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization. | ||
| CVE-2022-25906 | Hig | 0.48 | 7.4 | 0.01 | Feb 1, 2023 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. | ||
| CVE-2022-25962 | Hig | 0.48 | 7.4 | 0.01 | Jan 26, 2023 | All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. | ||
| CVE-2022-25908 | Hig | 0.48 | 7.4 | 0.02 | Jan 26, 2023 | All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization. | ||
| CVE-2022-25350 | Hig | 0.48 | 7.4 | 0.01 | Jan 26, 2023 | All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. | ||
| CVE-2022-21810 | Hig | 0.48 | 7.4 | 0.01 | Jan 26, 2023 | All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. | ||
| CVE-2022-25890 | Hig | 0.48 | 7.4 | 0.01 | Jan 9, 2023 | All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization. | ||
| CVE-2022-24431 | Hig | 0.48 | 7.4 | 0.01 | Dec 21, 2022 | All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization. | ||
| CVE-2022-4364 | Hig | 0.48 | 7.3 | 0.04 | Dec 8, 2022 | A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be… | ||
| CVE-2022-36962 | Hig | 0.48 | 7.2 | 0.09 | Nov 29, 2022 | SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands. | ||
| CVE-2022-2068 | Hig | 0.48 | 7.3 | 0.96 | Jun 21, 2022 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not… | ||
| CVE-2021-36287 | Hig | 0.48 | 7.3 | 0.03 | Apr 8, 2022 | Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system. | ||
| CVE-2021-42324 | Hig | 0.48 | 7.4 | 0.01 | Apr 5, 2022 | An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands… | ||
| CVE-2021-43266 | Hig | 0.48 | 7.3 | 0.01 | Nov 2, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause… | ||
| CVE-2021-23399 | Hig | 0.48 | 7.3 | 0.01 | Jun 28, 2021 | This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | ||
| CVE-2021-23381 | Hig | 0.48 | 7.3 | 0.01 | Apr 18, 2021 | This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. |
- risk 0.48cvss 6.3epss 0.88
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack…
- risk 0.48cvss 7.2epss 0.19
A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.
- risk 0.48cvss 7.3epss 0.02
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse…
- risk 0.48cvss 7.4epss 0.01
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
- risk 0.48cvss 7.4epss 0.01
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
- risk 0.48cvss 7.4epss 0.02
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
- risk 0.48cvss 7.4epss 0.01
All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.
- risk 0.48cvss 7.3epss 0.04
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be…
- risk 0.48cvss 7.2epss 0.09
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.
- risk 0.48cvss 7.3epss 0.96
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not…
- risk 0.48cvss 7.3epss 0.03
Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.
- risk 0.48cvss 7.4epss 0.01
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands…
- risk 0.48cvss 7.3epss 0.01
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause…
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- risk 0.48cvss 7.3epss 0.01
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.