VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 261 of 324
  • CVE-2023-39294MedJan 5, 2024
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-7002HigDec 23, 2023
    risk 0.43cvss 7.2epss 0.46

    The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execute arbitrary commands…

  • CVE-2023-34975MedOct 13, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the…

  • CVE-2023-32976MedOct 13, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Container Station…

  • CVE-2023-23355MedMar 29, 2023
    risk 0.43cvss 6.6epss 0.01

    An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote authenticated administrators to execute commands via unspecified vectors. QES is not affected. We have already fixed the…

  • CVE-2022-20964MedJan 20, 2023
    risk 0.43cvss 6.3epss 0.31

    A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user input within…

  • CVE-2021-23632MedMar 17, 2022
    risk 0.43cvss 6.6epss 0.02

    All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git method, which allows execution of OS commands rather than just git commands. Steps to Reproduce 1. Create a file named exploit.js with the following content: js…

  • CVE-2022-24753HigMar 9, 2022
    risk 0.43cvss 7.7epss 0.00

    Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe config -e`, `stripe community`, and…

  • CVE-2021-3198MedJul 22, 2021
    risk 0.43cvss 6.5epss 0.03

    By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.

  • CVE-2021-1473MedApr 8, 2021
    risk 0.43cvss 5.3epss 0.64

    Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities,…

  • CVE-2021-21345MedMar 23, 2021
    risk 0.43cvss 5.8epss 0.72

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user…

  • CVE-2020-7350MedApr 22, 2020
    risk 0.43cvss 6.1epss 0.05

    Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service name. An attacker can create a specially-crafted hostname or…

  • CVE-2019-6013MedDec 26, 2019
    risk 0.43cvss 6.6epss 0.01

    DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI).

  • CVE-2018-0643MedSep 7, 2018
    risk 0.43cvss 6.6epss 0.00

    Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

  • CVE-2014-3576HigAug 14, 2015
    risk 0.43cvss 7.5epss 0.10

    The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.

  • CVE-2026-73662HigAug 13, 2026
    risk 0.42cvss epss 0.01

    FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options…

  • CVE-2026-73660HigAug 13, 2026
    risk 0.42cvss epss 0.00

    FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to…

  • CVE-2026-73623HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary command execution during clone operations. Attackers can supply --template pointing to a directory containing malicious…

  • CVE-2026-17347HigJul 31, 2026
    risk 0.42cvss 7.5epss 0.00

    The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username…

  • CVE-2026-16445HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module.…