VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 285 of 324
  • CVE-2023-3607MedJul 10, 2023
    risk 0.36cvss 5.5epss 0.06

    A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to os command injection. The exploit has been disclosed to the…

  • CVE-2023-25555MedApr 18, 2023
    risk 0.36cvss 5.6epss 0.01

    A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. …

  • CVE-2022-20851MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2022-20797MedMay 27, 2022
    risk 0.36cvss 5.5epss 0.02

    A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system. This vulnerability…

  • CVE-2022-20718MedApr 15, 2022
    risk 0.36cvss 5.5epss 0.02

    Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install…

  • CVE-2020-7389MedJul 22, 2021
    risk 0.36cvss 5.5epss 0.02

    Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production.

  • CVE-2021-23380MedApr 18, 2021
    risk 0.36cvss 5.6epss 0.01

    This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function…

  • CVE-2021-1443MedMar 24, 2021
    risk 0.36cvss 5.5epss 0.02

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly…

  • CVE-2021-23356MedMar 15, 2021
    risk 0.36cvss 5.6epss 0.01

    This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file.

  • CVE-2021-23355MedMar 15, 2021
    risk 0.36cvss 5.6epss 0.01

    This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization in the index.js file.…

  • CVE-2020-7735MedSep 25, 2020
    risk 0.36cvss 6.6epss 0.02

    The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.

  • CVE-2020-24552MedSep 10, 2020
    risk 0.36cvss 5.5epss 0.01

    Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation, the device's web management interface allows attackers to inject specific code and execute system commands without privilege.

  • CVE-2019-14337MedAug 1, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequence.

  • CVE-2019-1725MedApr 18, 2019
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker could inject CLI command parameters that…

  • CVE-2016-7844MedAug 2, 2017
    risk 0.36cvss 5.5epss 0.01

    GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.

  • CVE-2016-6459MedNov 19, 2016
    risk 0.36cvss 5.5epss 0.01

    Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7…

  • CVE-2026-72881MedAug 10, 2026
    risk 0.35cvss epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, usernames, and passwords into…

  • CVE-2026-72739MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by interpolating compose service names and configuration into bash command strings. When a compose with a maliciously crafted name or service…

  • CVE-2026-36827MedMay 19, 2026
    risk 0.35cvss 5.4epss 0.01

    A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters to it. The helper performs unsafe argument processing using eval, which allows…

  • CVE-2026-31246MedMay 11, 2026
    risk 0.35cvss 6.5epss 0.01

    GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (CWE-78) in the Executor.run() method. During project execution, when the system prompts the user to confirm or modify a command to be run, it accepts free-text…