VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 73 of 327
  • CVE-2014-4981CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.06

    LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.

  • CVE-2020-9027CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.

  • CVE-2020-9026CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.

  • CVE-2020-9021CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.

  • CVE-2020-9020CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

  • CVE-2020-8963CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel…

  • CVE-2019-14514CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a…

  • CVE-2020-6760CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.

  • CVE-2019-10789CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.05

    All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

  • CVE-2019-10786CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.02

    network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

  • CVE-2019-10783CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.03

    All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

  • CVE-2019-20217CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/device is checked with the strstr function,…

  • CVE-2019-20216CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/device is checked with the strstr function,…

  • CVE-2013-2060CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.06

    The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.

  • CVE-2013-2612CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.03

    Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.

  • CVE-2014-8563CriJan 27, 2020
    risk 0.64cvss 9.8epss 0.03

    Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.

  • CVE-2019-19897CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.06

    In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target system by using the Execute Command Line…

  • CVE-2019-19839CriJan 23, 2020
    risk 0.64cvss 9.8epss 0.03

    emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.

  • CVE-2019-19842CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.05

    emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.

  • CVE-2019-19841CriJan 22, 2020
    risk 0.64cvss 9.8epss 0.03

    emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.