VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 276 of 324
  • CVE-2024-0714MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file userScripts.php of the component HTTP Request Handler. The manipulation of the argument folder with the input ;nc…

  • CVE-2024-0293MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.05

    A vulnerability classified as critical was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this vulnerability is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to os command injection. The attack can…

  • CVE-2024-0292MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.05

    A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument hostName leads to os command injection. It is possible to launch the attack…

  • CVE-2023-41289MedJan 5, 2024
    risk 0.41cvss 6.3epss 0.01

    An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later

  • CVE-2023-35895MedDec 20, 2023
    risk 0.41cvss 6.3epss 0.01

    IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.

  • CVE-2023-26145HigSep 28, 2023
    risk 0.41cvss 7.4epss 0.03

    This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths…

  • CVE-2023-4412MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects the function setWanCfg. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2023-4411MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.05

    A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2023-4410MedAug 18, 2023
    risk 0.41cvss 6.3epss 0.04

    A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects the function setDiagnosisCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed…

  • CVE-2023-3606MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.07

    A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part of the file /api/ping. The manipulation of the argument host leads to os command injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2023-33869MedJun 20, 2023
    risk 0.41cvss 6.3epss 0.01

    Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.

  • CVE-2023-0935MedFeb 21, 2023
    risk 0.41cvss 6.3epss 0.05

    A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file common.php of the component Incomplete Fix CVE-2021-46097. The manipulation of the argument id leads to os command…

  • CVE-2023-22643MedFeb 7, 2023
    risk 0.41cvss 6.3epss 0.02

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-plugin-appdata of SUSE Linux Enterprise Server for SAP 15-SP3; openSUSE Leap 15.4 allows attackers that can trick users to use specially crafted REPO_ALIAS,…

  • CVE-2022-25916HigFeb 1, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.

  • CVE-2022-21129HigJan 31, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium…

  • CVE-2022-21191HigJan 13, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.

  • CVE-2022-25923HigJan 6, 2023
    risk 0.41cvss 7.4epss 0.03

    Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionality due to improper user-input sanitization.

  • CVE-2022-25926HigJan 4, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

  • CVE-2022-25171HigDec 20, 2022
    risk 0.41cvss 7.4epss 0.02

    The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

  • CVE-2022-24377HigDec 14, 2022
    risk 0.41cvss 7.4epss 0.02

    The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.