VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 78 of 327
  • CVE-2018-19007CriDec 14, 2018
    risk 0.64cvss 9.8epss 0.04

    In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.

  • CVE-2018-12313CriDec 4, 2018
    risk 0.64cvss 9.8epss 0.04

    OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the "rocommunity" URL parameter.

  • CVE-2018-19290CriNov 30, 2018
    risk 0.64cvss 9.8epss 0.04

    In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the PHP daemon with a crafted command, resulting in a denial of service or possibly unspecified other impact, as demonstrated by the…

  • CVE-2018-19646CriNov 28, 2018
    risk 0.64cvss 9.8epss 0.03

    The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.

  • CVE-2018-13336CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.08

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.

  • CVE-2018-13316CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "subnet" POST parameter.

  • CVE-2018-13314CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formAliasIp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ipAddr" POST parameter.

  • CVE-2018-13307CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in fromNtp in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ntpServerIp2" POST parameter. Certain payloads cause the device to become permanently inoperable.

  • CVE-2018-13306CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.03

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.

  • CVE-2018-13311CriNov 26, 2018
    risk 0.64cvss 9.8epss 0.02

    System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.

  • CVE-2018-0694CriNov 15, 2018
    risk 0.64cvss 9.8epss 0.02

    FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-19168CriNov 11, 2018
    risk 0.64cvss 9.8epss 0.08

    Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a POST request. NOTE: unlike in CVE-2018-17317, the attacker…

  • CVE-2018-19081CriNov 7, 2018
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.

  • CVE-2018-16461CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.

  • CVE-2018-18728CriOct 29, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.

  • CVE-2018-12670CriOct 19, 2018
    risk 0.64cvss 9.8epss 0.03

    SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection.

  • CVE-2018-17787CriOct 2, 2018
    risk 0.64cvss 9.8epss 0.02

    On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.

  • CVE-2018-17317CriSep 21, 2018
    risk 0.64cvss 9.8epss 0.04

    FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_in_mask, io_in_gw, io_out_iface, io_out_set, io_out_mask, io_out_gw, iface, or…

  • CVE-2018-17228CriSep 19, 2018
    risk 0.64cvss 9.8epss 0.02

    nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.

  • CVE-2018-17068CriSep 15, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter.