CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,524)
page 65 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-27710 | Cri | 0.64 | 9.8 | 0.08 | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes… | ||
| CVE-2021-27708 | Cri | 0.64 | 9.8 | 0.08 | Apr 14, 2021 | Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes… | ||
| CVE-2021-27113 | Cri | 0.64 | 9.8 | 0.03 | Apr 14, 2021 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters. | ||
| CVE-2020-27227 | Cri | 0.64 | 9.8 | 0.03 | Apr 13, 2021 | An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability,… | ||
| CVE-2021-26810 | Cri | 0.64 | 9.8 | 0.05 | Mar 30, 2021 | D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the… | ||
| CVE-2020-24636 | Cri | 0.64 | 9.8 | 0.03 | Mar 29, 2021 | A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x:… | ||
| CVE-2020-1946 | Cri | 0.64 | 9.8 | 0.06 | Mar 25, 2021 | In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use… | ||
| CVE-2021-28132 | Cri | 0.64 | 9.8 | 0.03 | Mar 11, 2021 | LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI. | ||
| CVE-2021-3342 | Cri | 0.64 | 9.8 | 0.04 | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI. | ||
| CVE-2021-26476 | Cri | 0.64 | 9.8 | 0.03 | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI. | ||
| CVE-2019-25022 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation. | ||
| CVE-2021-20658 | Cri | 0.64 | 9.8 | 0.04 | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors. | ||
| CVE-2020-7786 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2021 | This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js. | ||
| CVE-2020-7785 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2021 | This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js. | ||
| CVE-2020-7782 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2021 | This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package. | ||
| CVE-2020-11920 | Cri | 0.64 | 9.8 | 0.04 | Feb 8, 2021 | An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shell metacharacters here, the device… | ||
| CVE-2020-2507 | Cri | 0.64 | 9.8 | 0.03 | Feb 3, 2021 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. | ||
| CVE-2020-7775 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2021 | This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js. | ||
| CVE-2021-3317 | Hig | 0.64 | 8.8 | 0.41 | Jan 26, 2021 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter. | ||
| CVE-2020-36199 | Cri | 0.64 | 9.8 | 0.02 | Jan 26, 2021 | TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places. |
- risk 0.64cvss 9.8epss 0.08
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes…
- risk 0.64cvss 9.8epss 0.08
Command Injection in TOTOLINK X5000R router with firmware v9.1.0u.6118_B20201102, and TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows remote attackers to execute arbitrary OS commands by sending a modified HTTP request. This occurs because the function executes…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/addRouting route. This could lead to Command Injection via Shell Metacharacters.
- risk 0.64cvss 9.8epss 0.03
An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability,…
- risk 0.64cvss 9.8epss 0.05
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the…
- risk 0.64cvss 9.8epss 0.03
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8.5.0.10 and below; Aruba Instant 8.6.x:…
- risk 0.64cvss 9.8epss 0.06
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use…
- risk 0.64cvss 9.8epss 0.03
LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a system.tar.gz file. The .php file becomes accessible with a public/system/static URI.
- risk 0.64cvss 9.8epss 0.04
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
- risk 0.64cvss 9.8epss 0.03
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation.
- risk 0.64cvss 9.8epss 0.04
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
- risk 0.64cvss 9.8epss 0.02
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
- risk 0.64cvss 9.8epss 0.02
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
- risk 0.64cvss 9.8epss 0.02
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shell metacharacters here, the device…
- risk 0.64cvss 9.8epss 0.03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
- risk 0.64cvss 9.8epss 0.01
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
- risk 0.64cvss 8.8epss 0.41
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
- risk 0.64cvss 9.8epss 0.02
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.