VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,529)

page 212 of 327
  • CVE-2023-4542MedAug 25, 2023
    risk 0.48cvss 6.3epss 0.88

    A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unknown part of the file /app/sys1.php. The manipulation of the argument cmd with the input id leads to os command injection. It is possible to initiate the attack…

  • CVE-2023-24261HigJun 21, 2023
    risk 0.48cvss 7.2epss 0.19

    A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code via a crafted POST request.

  • CVE-2023-26490HigMar 4, 2023
    risk 0.48cvss 7.3epss 0.02

    mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse…

  • CVE-2022-25855HigFeb 6, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

  • CVE-2022-25853HigFeb 6, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.

  • CVE-2022-25906HigFeb 1, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

  • CVE-2022-25962HigJan 26, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.

  • CVE-2022-25908HigJan 26, 2023
    risk 0.48cvss 7.4epss 0.02

    All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

  • CVE-2022-25350HigJan 26, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

  • CVE-2022-21810HigJan 26, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.

  • CVE-2022-25890HigJan 9, 2023
    risk 0.48cvss 7.4epss 0.01

    All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

  • CVE-2022-24431HigDec 21, 2022
    risk 0.48cvss 7.4epss 0.01

    All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.

  • CVE-2022-4364HigDec 8, 2022
    risk 0.48cvss 7.3epss 0.04

    A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be…

  • CVE-2022-36962HigNov 29, 2022
    risk 0.48cvss 7.2epss 0.09

    SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.

  • CVE-2022-2068HigJun 21, 2022
    risk 0.48cvss 7.3epss 0.96

    In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not…

  • CVE-2021-36287HigApr 8, 2022
    risk 0.48cvss 7.3epss 0.03

    Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.

  • CVE-2021-42324HigApr 5, 2022
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper parameter validation in the console interface, it is possible for a low-privileged authenticated attacker to escape the sandbox environment and execute system commands…

  • CVE-2021-43266HigNov 2, 2021
    risk 0.48cvss 7.3epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause…

  • CVE-2021-23399HigJun 28, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23381HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.