VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (2,016)

page 75 of 101
  • CVE-2021-36022Sep 1, 2021
    risk 0.01cvss epss 0.11

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

  • CVE-2021-21018Feb 11, 2021
    risk 0.01cvss epss 0.07

    Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the scheduled operation module. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin…

  • CVE-2019-10789Feb 6, 2020
    risk 0.01cvss epss 0.08

    All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

  • CVE-2018-3785Aug 17, 2018
    risk 0.01cvss epss 0.09

    A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter.

  • CVE-2014-4823Oct 3, 2014
    risk 0.01cvss epss 0.06

    The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inject system commands via unspecified…

  • CVE-2013-5946Dec 19, 2013
    risk 0.01cvss epss 0.06

    The runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allows remote…

  • CVE-2012-6601Aug 31, 2013
    risk 0.01cvss epss 0.09

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.

  • CVE-2011-2148May 20, 2011
    risk 0.01cvss epss 0.10

    Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPassword_SettingText…

  • CVE-2011-0271Jan 13, 2011
    risk 0.01cvss epss 0.13

    The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection…

  • CVE-2010-3757Oct 5, 2010
    risk 0.01cvss epss 0.07

    Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after…

  • CVE-2007-4041Jul 27, 2007
    risk 0.01cvss epss 0.11

    Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to…

  • CVE-2026-47751Jun 10, 2026
    risk 0.00cvss epss 0.00

    Due to the combination of checking out PR head branches (attacker-controlled), reading `.mcp.json` from the working directory via default setting sources, and unconditionally enabling all project MCP servers via `enableAllProjectMcpServers`, it was possible for an attacker who…

  • CVE-2026-46420May 20, 2026
    risk 0.00cvss epss 0.02

    ### Summary A command injection vulnerability was identified in `shivammathur/setup-php` when the action resolves the PHP version from repository-controlled files and uses that value while generating the platform setup script. In affected versions, `setup-php` may read the PHP…

  • CVE-2026-4821Apr 21, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.

  • CVE-2026-35022Apr 6, 2026
    risk 0.00cvss epss 0.01

    Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag behavior is documented in Anthropic's claude -h output with an explicit warning that non-interactive mode should only be used in trusted directories, making…

  • CVE-2026-35021Apr 6, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected code path cannot be triggered through normal usage of Claude Code.

  • CVE-2026-35020Apr 6, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the attack requires an attacker to already control arbitrary environment variables, a level of access they consider functionally equivalent to code execution and…

  • CVE-2026-27602Mar 25, 2026
    risk 0.00cvss epss 0.00

    Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` always runs subprocess calls with `shell=True`. Since domain names flow directly into shell command strings without any sanitization, a Reseller or SuperAdmin can…

  • CVE-2026-26831Mar 25, 2026
    risk 0.00cvss epss 0.01

    textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and…

  • CVE-2026-26833Mar 25, 2026
    risk 0.00cvss epss 0.00

    thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping.