VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 70 of 327
  • CVE-2014-7173CriJun 1, 2020
    risk 0.64cvss 9.8epss 0.03

    FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php.

  • CVE-2020-8171CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.04

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that…

  • CVE-2020-13388CriMay 22, 2020
    risk 0.64cvss 9.8epss 0.04

    An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because…

  • CVE-2020-7805CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.

  • CVE-2020-7646CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.02

    curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

  • CVE-2019-5623CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection').

  • CVE-2016-11061CriApr 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute…

  • CVE-2017-18858CriApr 28, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G 12.0.2.11 and earlier, M4300-52G 12.0.2.11 and earlier, M4300-28G-POE+ 12.0.2.11 and earlier, M4300-52G-POE+ 12.0.2.11 and earlier, M4300-8X8F 12.0.2.11 and…

  • CVE-2020-5868CriApr 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.

  • CVE-2018-21162CriApr 23, 2020
    risk 0.64cvss 9.8epss 0.03

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6250 before 1.0.4.8, R6300v2 before 1.0.4.6, R6400 before 1.0.1.12, R6700 before 1.0.1.16, R7000 before…

  • CVE-2020-11963CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced…

  • CVE-2020-10511CriApr 15, 2020
    risk 0.64cvss 9.8epss 0.02

    HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL.

  • CVE-2020-7614CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.04

    npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.

  • CVE-2020-7636CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.

  • CVE-2020-7635CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.

  • CVE-2020-7633CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

  • CVE-2020-7632CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

  • CVE-2020-7631CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.

  • CVE-2020-7630CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.

  • CVE-2020-7629CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.