CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,475)
page 314 of 324| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-37391 | Hig | 0.00 | 7.8 | 0.00 | Jul 22, 2024 | ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss. | ||
| CVE-2024-5181 | Cri | 0.00 | 9.8 | 0.03 | Jun 26, 2024 | A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this… | ||
| CVE-2024-1881 | Cri | 0.00 | 9.8 | 0.01 | Jun 6, 2024 | AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerability exists in versions v0.5.0… | ||
| CVE-2024-1880 | Hig | 0.00 | 7.8 | 0.01 | Jun 6, 2024 | An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the… | ||
| CVE-2024-3104 | Cri | 0.00 | 9.8 | 0.01 | Jun 6, 2024 | A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` endpoint, which allows for… | ||
| CVE-2024-4253 | Cri | 0.00 | 9.1 | 0.02 | Jun 4, 2024 | A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base… | ||
| CVE-2024-3126 | Hig | 0.00 | 8.4 | 0.01 | May 16, 2024 | A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The… | ||
| CVE-2024-3196 | Med | 0.00 | 6.7 | 0.02 | Apr 29, 2024 | A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects the function getStats/Services_silentDump/Services_stopStartMTA/Config_saveDateTime/Config_hostid/Logs_StartGetStat/dumpConfiguration of the component SOAP… | ||
| CVE-2024-3193 | Hig | 0.00 | 8.8 | 0.04 | Apr 29, 2024 | A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The… | ||
| CVE-2024-3191 | Cri | 0.00 | 9.8 | 0.05 | Apr 29, 2024 | A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has… | ||
| CVE-2024-30850 | 0.00 | — | — | Apr 12, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 instead of this record. All references and descriptions in this record have been removed to prevent… | |||
| CVE-2024-28187 | Hig | 0.00 | 7.2 | 0.02 | Mar 11, 2024 | SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulnerable to an OS Command Injection vulnerability within the file upload feature when accessed by an administrator. The vulnerability… | ||
| CVE-2022-48624 | Hig | 0.00 | 7.8 | 0.01 | Feb 19, 2024 | close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. | ||
| CVE-2023-51698 | Cri | 0.00 | 9.6 | 0.02 | Jan 12, 2024 | Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a… | ||
| CVE-2023-4222 | Hig | 0.00 | 7.2 | 0.04 | Nov 28, 2023 | Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | ||
| CVE-2023-4221 | Hig | 0.00 | 7.2 | 0.04 | Nov 28, 2023 | Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | ||
| CVE-2023-46117 | — | Hig | 0.00 | 8.8 | 0.01 | Oct 20, 2023 | reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities. A vulnerability has been identified in reconftw where inadequate validation of retrieved subdomains may lead to a… | |
| CVE-2023-45158 | Cri | 0.00 | 9.8 | 0.04 | Oct 16, 2023 | An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product. | ||
| CVE-2023-3975 | Cri | 0.00 | 9.8 | 0.02 | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0. | ||
| CVE-2023-3974 | Cri | 0.00 | 9.8 | 0.01 | Jul 27, 2023 | OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0. |
- risk 0.00cvss 7.8epss 0.00
ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.
- risk 0.00cvss 9.8epss 0.03
A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, which is used in the name of the initialized process. An attacker can exploit this…
- risk 0.00cvss 9.8epss 0.01
AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the vulnerability exists in versions v0.5.0…
- risk 0.00cvss 7.8epss 0.01
An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elements used in an OS command within the…
- risk 0.00cvss 9.8epss 0.01
A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` endpoint, which allows for…
- risk 0.00cvss 9.1epss 0.02
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.yml' workflow. The vulnerability arises due to improper neutralization of special elements used in a command, allowing for unauthorized modification of the base…
- risk 0.00cvss 8.4epss 0.01
A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The…
- risk 0.00cvss 6.7epss 0.02
A vulnerability was found in MailCleaner up to 2023.03.14. It has been declared as critical. This vulnerability affects the function getStats/Services_silentDump/Services_stopStartMTA/Config_saveDateTime/Config_hostid/Logs_StartGetStat/dumpConfiguration of the component SOAP…
- risk 0.00cvss 8.8epss 0.04
A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The…
- risk 0.00cvss 9.8epss 0.05
A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has…
- CVE-2024-30850Apr 12, 2024risk 0.00cvss —epss —
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 instead of this record. All references and descriptions in this record have been removed to prevent…
- risk 0.00cvss 7.2epss 0.02
SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulnerable to an OS Command Injection vulnerability within the file upload feature when accessed by an administrator. The vulnerability…
- risk 0.00cvss 7.8epss 0.01
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
- risk 0.00cvss 9.6epss 0.02
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the target system when the target user opens a crafted document or clicks on a crafted link/URL using a…
- risk 0.00cvss 7.2epss 0.04
Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
- risk 0.00cvss 7.2epss 0.04
Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters.
- risk 0.00cvss 8.8epss 0.01
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities. A vulnerability has been identified in reconftw where inadequate validation of retrieved subdomains may lead to a…
- risk 0.00cvss 9.8epss 0.04
An OS command injection vulnerability exists in web2py 2.24.1 and earlier. When the product is configured to use notifySendHandler for logging (not the default configuration), a crafted web request may execute an arbitrary OS command on the web server using the product.
- risk 0.00cvss 9.8epss 0.02
OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
- risk 0.00cvss 9.8epss 0.01
OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.