VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 63 of 324
  • CVE-2021-33191CriAug 24, 2021
    risk 0.64cvss 9.8epss 0.04

    From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an arbitrary value through a "c2-update"…

  • CVE-2021-31698CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.

  • CVE-2020-23151CriAug 9, 2021
    risk 0.64cvss 9.8epss 0.06

    rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.

  • CVE-2021-38196CriAug 8, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.

  • CVE-2021-36706CriAug 6, 2021
    risk 0.64cvss 9.8epss 0.03

    In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

  • CVE-2021-36705CriAug 6, 2021
    risk 0.64cvss 9.8epss 0.03

    In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.

  • CVE-2020-21937CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.05

    An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.

  • CVE-2020-21935CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.

  • CVE-2021-32534CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32533CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32531CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

  • CVE-2021-32530CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

  • CVE-2021-32513CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-32512CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of QSAN Storage Manager v3.3.3.

  • CVE-2021-28804CriJul 1, 2021
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build…

  • CVE-2021-28802CriJul 1, 2021
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerabilities have been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.1.1540 build…

  • CVE-2021-35047CriJun 25, 2021
    risk 0.64cvss 9.9epss 0.02

    Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis…

  • CVE-2021-21809CriJun 23, 2021
    risk 0.64cvss 9.1epss 0.24

    A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

  • CVE-2021-3013CriJun 11, 2021
    risk 0.64cvss 9.8epss 0.02

    ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.

  • CVE-2021-32605CriMay 11, 2021
    risk 0.64cvss 9.8epss 0.04

    zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.