VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 71 of 327
  • CVE-2020-7628CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.02

    umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

  • CVE-2020-7627CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.

  • CVE-2020-7626CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

  • CVE-2020-7624CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.04

    effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.

  • CVE-2020-7621CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.03

    strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.

  • CVE-2020-7620CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.02

    pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.

  • CVE-2020-7619CriApr 2, 2020
    risk 0.64cvss 9.8epss 0.02

    get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.

  • CVE-2019-19606CriMar 30, 2020
    risk 0.64cvss 9.8epss 0.02

    X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.

  • CVE-2020-10886CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tmpServer service, which…

  • CVE-2020-10882HigMar 25, 2020
    risk 0.64cvss 8.8epss 0.41

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…

  • CVE-2020-5561CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.02

    Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2020-5560CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.02

    WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.

  • CVE-2020-5556CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.02

    Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2019-12767CriMar 21, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.

  • CVE-2019-19148CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.08

    Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.

  • CVE-2018-20334CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

  • CVE-2020-10674CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.

  • CVE-2019-12132CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2019-12112CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2020-7607CriMar 15, 2020
    risk 0.64cvss 9.8epss 0.03

    gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.