CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,475)
page 315 of 324| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-36762 | Med | 0.00 | 5.5 | 0.02 | Jul 18, 2023 | A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection.… | ||
| CVE-2023-34108 | Hig | 0.00 | 8.8 | 0.01 | Jun 7, 2023 | mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using… | ||
| CVE-2023-31128 | Hig | 0.00 | 8.1 | 0.03 | May 26, 2023 | NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The… | ||
| CVE-2023-24805 | Hig | 0.00 | 8.8 | 0.04 | May 17, 2023 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote… | ||
| CVE-2023-30628 | Hig | 0.00 | 8.8 | 0.04 | Apr 24, 2023 | Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref`… | ||
| CVE-2023-30621 | Cri | 0.00 | 9.8 | 0.02 | Apr 21, 2023 | Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `… | ||
| CVE-2023-28627 | Hig | 0.00 | 8.3 | 0.01 | Mar 27, 2023 | pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web interface can update the git executable path in /config/general/ > advanced settings with arbitrary OS commands. An attacker may exploit this vulnerability to… | ||
| CVE-2023-1350 | Med | 0.00 | 6.3 | 0.02 | Mar 11, 2023 | A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to… | ||
| CVE-2022-43550 | Cri | 0.00 | 9.8 | 0.02 | Feb 9, 2023 | A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution. | ||
| CVE-2021-4281 | Med | 0.00 | 4.6 | 0.02 | Dec 26, 2022 | A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command injection. The name of the patch is… | ||
| CVE-2022-41751 | Hig | 0.00 | 7.8 | 0.00 | Oct 17, 2022 | Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option. | ||
| CVE-2022-3133 | Hig | 0.00 | 7.8 | 0.01 | Sep 9, 2022 | OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. | ||
| CVE-2022-3008 | Hig | 0.00 | 8.1 | 0.03 | Sep 5, 2022 | The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in… | ||
| CVE-2022-31138 | Hig | 0.00 | 8.8 | 0.03 | Jul 11, 2022 | mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or… | ||
| CVE-2021-32546 | Hig | 0.00 | 8.8 | 0.02 | Jun 2, 2022 | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that… | ||
| CVE-2022-1813 | Cri | 0.00 | 9.8 | 0.03 | May 22, 2022 | OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | ||
| CVE-2022-28055 | Cri | 0.00 | 9.8 | 0.01 | May 4, 2022 | Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function. | ||
| CVE-2022-24796 | Cri | 0.00 | 10.0 | 0.04 | Mar 31, 2022 | RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload facility of the WebUI interface of RaspberryMatic exists.… | ||
| CVE-2022-27811 | Cri | 0.00 | 9.8 | 0.03 | Mar 24, 2022 | GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename. | ||
| CVE-2022-24725 | Med | 0.00 | 6.2 | 0.01 | Mar 3, 2022 | Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`.… |
- risk 0.00cvss 5.5epss 0.02
A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection.…
- risk 0.00cvss 8.8epss 0.01
mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using…
- risk 0.00cvss 8.1epss 0.03
NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The…
- risk 0.00cvss 8.8epss 0.04
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote…
- risk 0.00cvss 8.8epss 0.04
Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref`…
- risk 0.00cvss 9.8epss 0.02
Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `…
- risk 0.00cvss 8.3epss 0.01
pymedusa is an automatic video library manager for TV Shows. In versions prior 1.0.12 an attacker with access to the web interface can update the git executable path in /config/general/ > advanced settings with arbitrary OS commands. An attacker may exploit this vulnerability to…
- risk 0.00cvss 6.3epss 0.02
A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to…
- risk 0.00cvss 9.8epss 0.02
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.
- risk 0.00cvss 4.6epss 0.02
A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command injection. The name of the patch is…
- risk 0.00cvss 7.8epss 0.00
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
- risk 0.00cvss 7.8epss 0.01
OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.
- risk 0.00cvss 8.1epss 0.03
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in…
- risk 0.00cvss 8.8epss 0.03
mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or…
- risk 0.00cvss 8.8epss 0.02
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that…
- risk 0.00cvss 9.8epss 0.03
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
- risk 0.00cvss 9.8epss 0.01
Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.
- risk 0.00cvss 10.0epss 0.04
RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload facility of the WebUI interface of RaspberryMatic exists.…
- risk 0.00cvss 9.8epss 0.03
GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.
- risk 0.00cvss 6.2epss 0.01
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`.…