CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,524)
page 71 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-7628 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2020 | umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. | ||
| CVE-2020-7627 | Cri | 0.64 | 9.8 | 0.04 | Apr 2, 2020 | node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function. | ||
| CVE-2020-7626 | Cri | 0.64 | 9.8 | 0.04 | Apr 2, 2020 | karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument. | ||
| CVE-2020-7624 | Cri | 0.64 | 9.8 | 0.04 | Apr 2, 2020 | effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument. | ||
| CVE-2020-7621 | Cri | 0.64 | 9.8 | 0.03 | Apr 2, 2020 | strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function. | ||
| CVE-2020-7620 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2020 | pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params. | ||
| CVE-2020-7619 | Cri | 0.64 | 9.8 | 0.02 | Apr 2, 2020 | get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data. | ||
| CVE-2019-19606 | Cri | 0.64 | 9.8 | 0.02 | Mar 30, 2020 | X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system. | ||
| CVE-2020-10886 | Cri | 0.64 | 9.8 | 0.06 | Mar 25, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tmpServer service, which… | ||
| CVE-2020-10882 | Hig | 0.64 | 8.8 | 0.41 | Mar 25, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,… | ||
| CVE-2020-5561 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2020 | Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2020-5560 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2020 | WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors. | ||
| CVE-2020-5556 | Cri | 0.64 | 9.8 | 0.02 | Mar 25, 2020 | Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | ||
| CVE-2019-12767 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2020 | An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands. | ||
| CVE-2019-19148 | Cri | 0.64 | 9.8 | 0.08 | Mar 20, 2020 | Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020. | ||
| CVE-2018-20334 | Cri | 0.64 | 9.8 | 0.04 | Mar 20, 2020 | An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell. | ||
| CVE-2020-10674 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2020 | PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open. | ||
| CVE-2019-12132 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2020 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected. | ||
| CVE-2019-12112 | Cri | 0.64 | 9.8 | 0.01 | Mar 18, 2020 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected. | ||
| CVE-2020-7607 | Cri | 0.64 | 9.8 | 0.03 | Mar 15, 2020 | gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization. |
- risk 0.64cvss 9.8epss 0.02
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
- risk 0.64cvss 9.8epss 0.04
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
- risk 0.64cvss 9.8epss 0.04
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
- risk 0.64cvss 9.8epss 0.04
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
- risk 0.64cvss 9.8epss 0.03
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
- risk 0.64cvss 9.8epss 0.02
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
- risk 0.64cvss 9.8epss 0.02
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
- risk 0.64cvss 9.8epss 0.02
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.
- risk 0.64cvss 9.8epss 0.06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tmpServer service, which…
- risk 0.64cvss 8.8epss 0.41
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…
- risk 0.64cvss 9.8epss 0.02
Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- risk 0.64cvss 9.8epss 0.02
WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.
- risk 0.64cvss 9.8epss 0.02
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.08
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.
- risk 0.64cvss 9.8epss 0.01
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
- risk 0.64cvss 9.8epss 0.03
gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization.