VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 75 of 327
  • CVE-2019-17526CriOct 18, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an…

  • CVE-2019-17510CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizardConfig.php.

  • CVE-2019-17509CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php.

  • CVE-2019-17059CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.07

    A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

  • CVE-2019-12812CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.03

    MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution.

  • CVE-2019-12811CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.02

    ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method. This can be leveraged for code execution

  • CVE-2019-15746CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.02

    SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.

  • CVE-2019-17269CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.03

    Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.

  • CVE-2019-13025CriOct 2, 2019
    risk 0.64cvss 9.8epss 0.03

    Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Validation. The attacker can send a maliciously modified POST (HTTP) request containing shell commands, which will be executed on the device, to an backend API…

  • CVE-2019-15000CriSep 19, 2019
    risk 0.64cvss 9.8epss 0.08

    The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x),…

  • CVE-2019-15503CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

  • CVE-2019-1581CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated remote users with network access to the SSH management interface gaining root access to PAN-OS. This issue affects PAN-OS 7.1 versions prior to 7.1.24-h1, 7.1.25;…

  • CVE-2019-15490CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.02

    openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.

  • CVE-2019-14527CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication.

  • CVE-2019-12103CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulnerability.

  • CVE-2019-15027CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in…

  • CVE-2019-1971CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input…

  • CVE-2019-14699CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web…

  • CVE-2019-1010179CriJul 24, 2019
    risk 0.64cvss 9.8epss 0.02

    PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to manipulate gpg-keys or execute commands remotely. The component is: function…

  • CVE-2019-1010245CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.03

    The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerMan…