VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 302 of 324
  • CVE-2010-3039Nov 9, 2010
    risk 0.04cvss epss 0.09

    /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs…

  • CVE-2010-1132Mar 27, 2010
    risk 0.04cvss epss 0.09

    The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

  • CVE-2009-1916Jun 4, 2009
    risk 0.04cvss epss 0.10

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.

  • CVE-2008-3076Feb 21, 2009
    risk 0.04cvss epss 0.09

    The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test…

  • CVE-2007-5322Oct 9, 2007
    risk 0.04cvss epss 0.19

    Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.

  • CVE-2002-1660Dec 31, 2002
    risk 0.04cvss epss 0.11

    calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

  • CVE-2026-48778HigJun 26, 2026
    risk 0.03cvss 7.8epss 0.01

    Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the tag in config.xml is read by NppXml::value() (Parameters.cpp:6430) and stored in _nppGUI._commandLineInterpreter without any validation, whitelist, or digital…

  • CVE-2024-12828HigDec 30, 2024
    risk 0.03cvss 8.8epss 0.33

    Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of…

  • CVE-2023-2564CriMay 7, 2023
    risk 0.03cvss 10.0epss 0.41

    OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

  • CVE-2023-26482CriMar 30, 2023
    risk 0.03cvss 9.0epss 0.04

    Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order…

  • CVE-2019-25066MedJun 9, 2022
    risk 0.03cvss 6.3epss 0.05

    A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…

  • CVE-2015-7901Oct 28, 2015
    risk 0.03cvss epss 0.03

    Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

  • CVE-2015-6008Sep 28, 2015
    risk 0.03cvss epss 0.05

    install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.

  • CVE-2013-6041Dec 27, 2014
    risk 0.03cvss epss 0.04

    index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

  • CVE-2013-3365Feb 4, 2014
    risk 0.03cvss epss 0.04

    TRENDnet TEW-812DRU router allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) wan network prefix to internet/ipv6.asp; (2) remote port to adm/management.asp; (3) pptp username, (4) pptp password, (5) ip, (6) gateway, (7) l2tp…

  • CVE-2012-2986Aug 20, 2012
    risk 0.03cvss epss 0.04

    lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first, (2) third, or (3) fourth parameter. NOTE: this vulnerability exists because of an incomplete fix…

  • CVE-2011-1513Nov 4, 2011
    risk 0.03cvss epss 0.06

    Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

  • CVE-2009-3233Sep 17, 2009
    risk 0.03cvss epss 0.01

    changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.

  • CVE-2008-6669Apr 8, 2009
    risk 0.03cvss epss 0.04

    viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.

  • CVE-2007-5653Oct 23, 2007
    risk 0.03cvss epss 0.05

    The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by executing objects with the kill bit set in the corresponding…