VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 317 of 324
  • CVE-2021-23330CriFeb 1, 2021
    risk 0.00cvss 9.8epss 0.05

    All versions of package launchpad are vulnerable to Command Injection via stop.

  • CVE-2021-3190CriJan 26, 2021
    risk 0.00cvss 9.8epss 0.05

    The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.

  • CVE-2020-7781CriDec 16, 2020
    risk 0.00cvss 9.8epss 0.02

    This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:

  • CVE-2020-15272HigOct 26, 2020
    risk 0.00cvss 8.7epss 0.01

    In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has…

  • CVE-2020-15121HigJul 20, 2020
    risk 0.00cvss 7.4epss 0.02

    In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned…

  • CVE-2020-7206CriJul 17, 2020
    risk 0.00cvss 9.8epss 0.02

    HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.

  • CVE-2020-13252HigMay 21, 2020
    risk 0.00cvss 8.8epss 0.05

    Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.

  • CVE-2020-7645CriMay 2, 2020
    risk 0.00cvss 9.8epss 0.01

    All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.

  • CVE-2020-11016CriApr 30, 2020
    risk 0.00cvss 9.1epss 0.02

    IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled messages given by user-input in the "send" functionality of the Inspect-tool of the Monitor component. An attacker with access to the IntelMQ Manager could…

  • CVE-2020-7625CriApr 2, 2020
    risk 0.00cvss 9.8epss 0.04

    op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.

  • CVE-2020-10789CriMar 25, 2020
    risk 0.00cvss 9.8epss 0.02

    openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.

  • CVE-2019-16790MedDec 30, 2019
    risk 0.00cvss 6.5epss 0.01

    In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.

  • CVE-2019-16964HigOct 21, 2019
    risk 0.00cvss 8.8epss 0.02

    app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_center_queue_add or call_center_queue_edit)…

  • CVE-2019-13139HigAug 22, 2019
    risk 0.00cvss 8.4epss 0.02

    In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the…

  • CVE-2019-1010200CriJul 23, 2019
    risk 0.00cvss 9.8epss 0.02

    Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). The impact is: Remote code execution with the…

  • CVE-2019-11410HigJun 17, 2019
    risk 0.00cvss 7.2epss 0.03

    app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.

  • CVE-2019-12839HigJun 15, 2019
    risk 0.00cvss 8.8epss 0.04

    In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.

  • CVE-2019-12585CriJun 3, 2019
    risk 0.00cvss 9.8epss 0.05

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

  • CVE-2018-6342CriDec 31, 2018
    risk 0.00cvss 9.8epss 0.03

    react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF…

  • CVE-2018-6353HigJan 27, 2018
    risk 0.00cvss 7.8epss 0.00

    The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended…