VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 5 of 324
  • CVE-2024-8517CriSep 6, 2024
    risk 0.74cvss 9.8epss 0.95

    SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

  • CVE-2023-40504CriMay 3, 2024
    risk 0.74cvss 9.8epss 0.88

    LG Simple Editor readVideoInfo Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2023-28343CriMar 14, 2023
    risk 0.74cvss 9.8epss 0.85

    OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

  • CVE-2016-20016CriOct 19, 2022
    risk 0.74cvss 9.8epss 0.87

    MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS…

  • CVE-2021-46422CriApr 27, 2022
    risk 0.74cvss 9.8epss 0.95

    Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

  • CVE-2021-20837CriOct 26, 2021
    risk 0.74cvss 9.8epss 0.88

    Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type…

  • CVE-2021-3122CriFeb 7, 2021
    risk 0.74cvss 9.8epss 0.87

    CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbitrary command as SYSTEM, as exploited in the wild in 2020…

  • CVE-2020-35729CriDec 27, 2020
    risk 0.74cvss 9.8epss 0.88

    KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.

  • CVE-2020-28188CriDec 24, 2020
    risk 0.74cvss 9.8epss 0.97

    Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.

  • CVE-2020-35476CriDec 16, 2020
    risk 0.74cvss 9.8epss 0.85

    A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java…

  • CVE-2020-13151CriAug 5, 2020
    risk 0.74cvss 9.8epss 0.87

    Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with…

  • CVE-2020-13167CriMay 19, 2020
    risk 0.74cvss 9.8epss 0.95

    Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

  • CVE-2011-2523CriNov 27, 2019
    risk 0.74cvss 9.8epss 0.96

    vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

  • CVE-2019-12725CriJul 19, 2019
    risk 0.74cvss 9.8epss 0.90

    Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

  • CVE-2018-14417CriAug 4, 2018
    risk 0.74cvss 9.8epss 0.90

    A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary…

  • CVE-2017-17411CriDec 21, 2017
    risk 0.74cvss 9.8epss 0.88

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper…

  • CVE-2024-47407CriNov 22, 2024
    risk 0.73cvss 10.0epss 0.64

    A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

  • CVE-2023-49897HigKEVDec 6, 2023
    risk 0.73cvss 8.8epss 0.51

    An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2023-6019CriNov 16, 2023
    risk 0.73cvss 9.8epss 0.75

    A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here:…

  • CVE-2022-2884CriOct 17, 2022
    risk 0.73cvss 9.9epss 0.76

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint