CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,524)
page 241 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11184 | Hig | 0.47 | 7.2 | 0.04 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 42 of 46). | ||
| CVE-2018-11163 | Hig | 0.47 | 7.2 | 0.04 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 21 of 46). | ||
| CVE-2018-11151 | Hig | 0.47 | 7.2 | 0.04 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46). | ||
| CVE-2018-1239 | Hig | 0.47 | 7.2 | 0.03 | May 8, 2018 | Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system… | ||
| CVE-2018-10431 | Hig | 0.47 | 7.2 | 0.02 | Apr 26, 2018 | D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen. | ||
| CVE-2018-7046 | Hig | 0.47 | 7.2 | 0.04 | Feb 20, 2018 | Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. … | ||
| CVE-2018-6926 | Hig | 0.47 | 7.2 | 0.01 | Feb 12, 2018 | In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The… | ||
| CVE-2018-1185 | Med | 0.47 | 6.7 | 0.06 | Feb 3, 2018 | An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape… | ||
| CVE-2017-16641 | Hig | 0.47 | 7.2 | 0.03 | Nov 7, 2017 | lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php. | ||
| CVE-2017-7341 | Hig | 0.47 | 7.2 | 0.04 | Oct 26, 2017 | An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system console commands via… | ||
| CVE-2017-14405 | Hig | 0.47 | 7.2 | 0.03 | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php. | ||
| CVE-2017-2275 | Hig | 0.47 | 7.2 | 0.01 | Jul 22, 2017 | WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2016-7819 | Hig | 0.47 | 7.2 | 0.02 | Jun 9, 2017 | I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2017-2141 | Hig | 0.47 | 7.2 | 0.01 | Apr 28, 2017 | WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2017-3796 | Hig | 0.47 | 7.2 | 0.02 | Jan 26, 2017 | A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6. | ||
| CVE-2016-6373 | Hig | 0.47 | 7.2 | 0.02 | Sep 22, 2016 | The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541. | ||
| CVE-2026-53790 | Hig | 0.46 | 8.1 | 0.01 | Aug 13, 2026 | rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl… | ||
| CVE-2026-17248 | Hig | 0.46 | 7.1 | 0.00 | Aug 12, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command. | ||
| CVE-2026-55173 | Hig | 0.46 | 8.1 | 0.02 | Jul 16, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-33482 reported that… | ||
| CVE-2026-44454 | Hig | 0.46 | 8.1 | 0.01 | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user… |
- risk 0.47cvss 7.2epss 0.04
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 42 of 46).
- risk 0.47cvss 7.2epss 0.04
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 21 of 46).
- risk 0.47cvss 7.2epss 0.04
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46).
- risk 0.47cvss 7.2epss 0.03
Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to execute arbitrary OS commands as system root on the system…
- risk 0.47cvss 7.2epss 0.02
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
- risk 0.47cvss 7.2epss 0.04
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. …
- risk 0.47cvss 7.2epss 0.01
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The…
- risk 0.47cvss 6.7epss 0.06
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0.0, and EMC RecoverPoint versions prior to 5.0.1.3. Command injection vulnerability in Admin CLI may allow a malicious user with admin privileges to escape…
- risk 0.47cvss 7.2epss 0.03
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
- risk 0.47cvss 7.2epss 0.04
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system console commands via…
- risk 0.47cvss 7.2epss 0.03
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
- risk 0.47cvss 7.2epss 0.01
WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
- risk 0.47cvss 7.2epss 0.02
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- risk 0.47cvss 7.2epss 0.01
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.
- risk 0.47cvss 7.2epss 0.02
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6.
- risk 0.47cvss 7.2epss 0.02
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.
- risk 0.46cvss 8.1epss 0.01
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl…
- risk 0.46cvss 7.1epss 0.00
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.
- risk 0.46cvss 8.1epss 0.02
WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-33482 reported that…
- risk 0.46cvss 8.1epss 0.01
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user…