VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 88 of 327
  • CVE-2024-9166CriSep 26, 2024
    risk 0.61cvss epss 0.02

    The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

  • CVE-2024-1624CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.02

    An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA…

  • CVE-2023-6018CriNov 16, 2023
    risk 0.61cvss 9.8epss 0.48

    An attacker can overwrite any file on the server hosting MLflow without any authentication.

  • CVE-2022-47555CriSep 19, 2023
    risk 0.61cvss 9.3epss 0.01

    Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

  • CVE-2023-33012HigJul 17, 2023
    risk 0.61cvss 8.8epss 0.10

    A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series…

  • CVE-2022-38841HigApr 16, 2023
    risk 0.61cvss 8.8epss 0.11

    Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

  • CVE-2023-27826HigApr 12, 2023
    risk 0.61cvss 8.8epss 0.12

    SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. which allows attackers to take over the system with root privilege by abusing doSystem() function.

  • CVE-2022-46552HigFeb 2, 2023
    risk 0.61cvss 8.8epss 0.10

    D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2020-28435CriJul 25, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

  • CVE-2022-30023HigJun 16, 2022
    risk 0.61cvss 8.8epss 0.39

    Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

  • CVE-2021-42165HigMay 3, 2022
    risk 0.61cvss 8.8epss 0.14

    MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing command "deviceinfo show file &&/bin/bash" because of incorrect sanitization of parameter "path".

  • CVE-2022-25017CriApr 1, 2022
    risk 0.61cvss 9.1epss 0.29

    Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.

  • CVE-2022-22951CriMar 23, 2022
    risk 0.61cvss 9.1epss 0.20

    VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control…

  • CVE-2020-3586CriNov 18, 2020
    risk 0.61cvss 9.4epss 0.02

    A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insufficient validation of user-supplied input in the web-based…

  • CVE-2020-24365HigSep 24, 2020
    risk 0.61cvss 8.8epss 0.11

    An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed as the root user (uid 0). (Even if a…

  • CVE-2020-11699HigSep 17, 2020
    risk 0.61cvss 8.8epss 0.10

    An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.

  • CVE-2020-23934HigAug 18, 2020
    risk 0.61cvss 8.8epss 0.16

    An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.

  • CVE-2020-8816HigKEVMay 29, 2020
    risk 0.61cvss 7.2epss 0.78

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

  • CVE-2019-20501HigMar 5, 2020
    risk 0.61cvss 7.8epss 0.90

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or firmwareServerip parameter.

  • CVE-2019-20499HigMar 5, 2020
    risk 0.61cvss 7.8epss 0.95

    D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRestore or configServerip parameter.