VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 55 of 324
  • CVE-2022-40929CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

  • CVE-2022-28811CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

  • CVE-2022-38826CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

  • CVE-2022-39815CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.02

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

  • CVE-2022-33941CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.02

    PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected…

  • CVE-2022-36566CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

  • CVE-2022-36749CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.03

    RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.

  • CVE-2022-37149CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.03

    WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

  • CVE-2022-37810CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC1206 V15.03.06.23 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

  • CVE-2021-42232CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.04

    TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on…

  • CVE-2022-36273CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

  • CVE-2022-22140CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.04

    An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2022-21178CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.04

    An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this…

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2022-23100CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

  • CVE-2020-28447CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

  • CVE-2022-28375CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into…

  • CVE-2022-28373CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject shell metacharacters to…

  • CVE-2022-28888CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.04

    Spryker Commerce OS 1.4.2 allows Remote Command Execution.

  • CVE-2022-34597CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.