VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 239 of 327
  • CVE-2019-10048HigMay 31, 2019
    risk 0.47cvss 7.2epss 0.03

    The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation and sanitization of user supplied input in the plugin's configuration options, allowing arbitrary shell commands to be entered that result in command execution…

  • CVE-2018-7082HigMay 10, 2019
    risk 0.47cvss 7.2epss 0.04

    A command injection vulnerability is present in Aruba Instant that permits an authenticated administrative user to execute arbitrary commands on the underlying operating system. A malicious administrator could use this ability to install backdoors or change system configuration…

  • CVE-2019-7301HigFeb 1, 2019
    risk 0.47cvss 7.2epss 0.03

    Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.

  • CVE-2018-12237HigJan 24, 2019
    risk 0.47cvss 7.2epss 0.03

    The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.

  • CVE-2018-16194HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-0639HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0638HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.

  • CVE-2018-0637HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.

  • CVE-2018-0636HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.

  • CVE-2018-0635HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

  • CVE-2018-0634HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.

  • CVE-2018-0631HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0630HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.

  • CVE-2018-0629HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0628HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0627HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0626HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.

  • CVE-2018-0625HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

  • CVE-2018-19239HigDec 20, 2018
    risk 0.47cvss 7.2epss 0.04

    TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi…

  • CVE-2018-13330HigNov 27, 2018
    risk 0.47cvss 7.2epss 0.08

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands during group creation via the "groupname" parameter.