VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 316 of 324
  • CVE-2022-25328MedFeb 25, 2022
    risk 0.00cvss 5.0epss 0.00

    The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a…

  • CVE-2022-23611HigFeb 4, 2022
    risk 0.00cvss 8.1epss 0.01

    iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commit cdcd48b. Users are advised to upgrade.

  • CVE-2021-45845HigJan 25, 2022
    risk 0.00cvss 7.8epss 0.02

    The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.

  • CVE-2021-3584HigDec 23, 2021
    risk 0.00cvss 7.2epss 0.04

    A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity…

  • CVE-2021-3769HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a…

  • CVE-2021-3727HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols,…

  • CVE-2021-3726HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function…

  • CVE-2021-3725HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name,…

  • CVE-2021-41280CriNov 19, 2021
    risk 0.00cvss 9.8epss 0.03

    Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is possible on installations of Sharetribe Go, that do not have a secret AWS Simple Notification Service (SNS) notification token configured via the…

  • CVE-2021-3934HigNov 12, 2021
    risk 0.00cvss 7.5epss 0.01

    ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command

  • CVE-2021-37158HigNov 10, 2021
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

  • CVE-2020-22345HigAug 18, 2021
    risk 0.00cvss 8.8epss 0.04

    /graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.

  • CVE-2021-38305HigAug 9, 2021
    risk 0.00cvss 7.8epss 0.02

    23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the eval. When processing…

  • CVE-2021-32749MedJul 16, 2021
    risk 0.00cvss 6.1epss 0.04

    fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from…

  • CVE-2021-21414HigApr 29, 2021
    risk 0.00cvss 7.7epss 0.02

    Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerability. This issue may lead to remote code execution if a client of the library…

  • CVE-2021-21433CriApr 9, 2021
    risk 0.00cvss 9.9epss 0.03

    Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow remote users to execute commands on the server resulting in serious issues. This flaw is patched in 0.0.2.

  • CVE-2021-21372HigMar 26, 2021
    risk 0.00cvss 8.3epss 0.04

    Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, Nimble doCmd is used in different places and can be leveraged to execute arbitrary commands. An attacker can craft a malicious entry in the packages.json…

  • CVE-2021-28961HigMar 21, 2021
    risk 0.00cvss 8.8epss 0.02

    applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

  • CVE-2021-21302MedFeb 26, 2021
    risk 0.00cvss 6.8epss 0.01

    PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2

  • CVE-2021-26541CriFeb 8, 2021
    risk 0.00cvss 9.8epss 0.05

    The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.