VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 66 of 327
  • CVE-2020-35576HigJan 26, 2021
    risk 0.64cvss 8.8epss 0.42

    A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.

  • CVE-2021-1142CriJan 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2021-1141CriJan 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2021-1140CriJan 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2021-1139CriJan 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2021-1138CriJan 20, 2021
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabilities, see the Details section of this…

  • CVE-2020-5685CriJan 13, 2021
    risk 0.64cvss 9.8epss 0.02

    UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.

  • CVE-2020-35458CriJan 12, 2021
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.

  • CVE-2020-7794CriJan 8, 2021
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).

  • CVE-2020-7784CriJan 8, 2021
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:

  • CVE-2021-3029CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.03

    EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain root access. NOTE: This vulnerability only affects…

  • CVE-2020-36178CriJan 6, 2021
    risk 0.64cvss 9.8epss 0.10

    oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE:…

  • CVE-2020-29552CriDec 23, 2020
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.

  • CVE-2020-25094CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.03

    LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run…

  • CVE-2020-20184CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.03

    GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.

  • CVE-2020-28440CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

  • CVE-2020-28439CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

  • CVE-2020-15357CriDec 11, 2020
    risk 0.64cvss 9.8epss 0.04

    Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping, traceroute, or route options.

  • CVE-2020-29311CriDec 10, 2020
    risk 0.64cvss 9.8epss 0.06

    Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.

  • CVE-2020-19527CriDec 10, 2020
    risk 0.64cvss 9.8epss 0.02

    iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.