VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 80 of 327
  • CVE-2017-14478CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.06

    In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the…

  • CVE-2017-14477CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.06

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the…

  • CVE-2017-14476CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.06

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the…

  • CVE-2017-14475CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.06

    In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the…

  • CVE-2017-14474CriMay 9, 2018
    risk 0.64cvss 9.8epss 0.06

    In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process.…

  • CVE-2018-1144CriApr 19, 2018
    risk 0.64cvss 9.8epss 0.06

    A remote unauthenticated user can execute commands as root in the Belkin N750 using firmware version 1.10.22 by sending a crafted HTTP request to proxy.cgi.

  • CVE-2018-0545CriApr 9, 2018
    risk 0.64cvss 9.8epss 0.03

    LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-9285CriApr 4, 2018
    risk 0.64cvss 9.8epss 0.03

    Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices…

  • CVE-2018-0539CriMar 22, 2018
    risk 0.64cvss 9.8epss 0.02

    QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.

  • CVE-2018-6231CriMar 15, 2018
    risk 0.64cvss 9.8epss 0.06

    A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.

  • CVE-2017-7640CriMar 8, 2018
    risk 0.64cvss 9.8epss 0.02

    QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.

  • CVE-2018-7664CriMar 5, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php.

  • CVE-2018-7440CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.

  • CVE-2017-14535HigFeb 16, 2018
    risk 0.64cvss 8.8epss 0.50

    trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

  • CVE-2018-1000043CriFeb 9, 2018
    risk 0.64cvss 9.8epss 0.04

    Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be…

  • CVE-2018-1000042CriFeb 9, 2018
    risk 0.64cvss 9.8epss 0.04

    Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be…

  • CVE-2018-0514CriFeb 8, 2018
    risk 0.64cvss 9.8epss 0.02

    MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-0506CriJan 26, 2018
    risk 0.64cvss 9.8epss 0.02

    Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2017-17407CriJan 23, 2018
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content…

  • CVE-2017-16608CriJan 23, 2018
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from the lack of proper…