VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 300 of 324
  • CVE-2012-4177Aug 7, 2012
    risk 0.08cvss epss 0.58

    The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.

  • CVE-2012-2953Jul 23, 2012
    risk 0.08cvss epss 0.67

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

  • CVE-2022-24697CriOct 13, 2022
    risk 0.07cvss 9.8epss 0.85

    Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system…

  • CVE-2019-19609HigDec 5, 2019
    risk 0.07cvss 7.2epss 0.54

    The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa…

  • CVE-2012-4361Aug 20, 2012
    risk 0.07cvss epss 0.48

    lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter.

  • CVE-2010-1423Apr 15, 2010
    risk 0.07cvss epss 0.56

    Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2)…

  • CVE-1999-0067Mar 20, 1996
    risk 0.07cvss epss 0.87

    phf CGI program allows remote command execution through shell metacharacters.

  • CVE-2023-3368CriNov 28, 2023
    risk 0.06cvss 9.8epss 0.70

    Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960.

  • CVE-2022-0848CriMar 4, 2022
    risk 0.06cvss 9.8epss 0.35

    OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

  • CVE-2020-7357CriAug 6, 2020
    risk 0.06cvss 9.6epss 0.32

    Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue…

  • CVE-2013-0928Jan 21, 2013
    risk 0.06cvss epss 0.34

    The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run command" operation.

  • CVE-2012-2516Jul 5, 2012
    risk 0.06cvss epss 0.40

    An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20…

  • CVE-2009-4498Dec 31, 2009
    risk 0.06cvss epss 0.32

    The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.

  • CVE-2009-2011Jun 16, 2009
    risk 0.06cvss epss 0.40

    Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a…

  • CVE-2020-14947HigJun 30, 2020
    risk 0.05cvss 8.8epss 0.19

    OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.

  • CVE-2019-12735HigJun 5, 2019
    risk 0.05cvss 8.6epss 0.19

    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

  • CVE-2014-8387Nov 20, 2014
    risk 0.05cvss epss 0.31

    cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

  • CVE-2013-6719Mar 6, 2014
    risk 0.05cvss epss 0.27

    delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

  • CVE-2012-5863Nov 23, 2012
    risk 0.05cvss epss 0.25

    These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly…

  • CVE-2012-3001Oct 22, 2012
    risk 0.05cvss epss 0.27

    Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."