VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 98 of 327
  • CVE-2020-26838CriDec 9, 2020
    risk 0.59cvss 9.1epss 0.02

    SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted request to generate and execute code without requiring any…

  • CVE-2020-14324CriAug 11, 2020
    risk 0.59cvss 9.1epss 0.03

    A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw…

  • CVE-2020-13782HigJun 3, 2020
    risk 0.59cvss 8.8epss 0.27

    D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.

  • CVE-2019-19824HigJan 27, 2020
    risk 0.59cvss 8.8epss 0.25

    On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects…

  • CVE-2019-17096CriJan 27, 2020
    risk 0.59cvss 9.0epss 0.02

    A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.

  • CVE-2019-20197HigDec 31, 2019
    risk 0.59cvss 8.8epss 0.22

    In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

  • CVE-2019-19642HigDec 8, 2019
    risk 0.59cvss 8.8epss 0.19

    On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in…

  • CVE-2019-18839CriNov 13, 2019
    risk 0.59cvss 9.0epss 0.05

    FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will…

  • CVE-2019-14423HigOct 17, 2019
    risk 0.59cvss 8.8epss 0.20

    A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.

  • CVE-2019-17625CriOct 16, 2019
    risk 0.59cvss 9.0epss 0.03

    There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing a service. The problem occurs due to incorrect sanitization of the name field when being processed and stored. This allows a user to craft a payload for…

  • CVE-2019-5475HigSep 3, 2019
    risk 0.59cvss 8.8epss 0.17

    The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

  • CVE-2019-12328CriJul 22, 2019
    risk 0.59cvss 9.0epss 0.04

    A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigger OS commands via shell metacharacters…

  • CVE-2018-14860CriJul 3, 2019
    risk 0.59cvss 9.1epss 0.02

    Improper sanitization of dynamic user expressions in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated privileged users to escape from the dynamic expression sandbox and execute arbitrary code on the hosting system.

  • CVE-2019-3409CriJun 11, 2019
    risk 0.59cvss 9.0epss 0.02

    All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerability. Due to inadequate parameter verification, unauthorized users can take advantage of this vulnerability to control the user terminal system.

  • CVE-2019-12739CriJun 5, 2019
    risk 0.59cvss 9.0epss 0.03

    lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).

  • CVE-2018-4061HigMay 6, 2019
    risk 0.59cvss 8.8epss 0.15

    An exploitable command injection vulnerability exists in the ACEManager iplogging.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP request can inject arbitrary commands, resulting in arbitrary command execution. An attacker can send an…

  • CVE-2018-13358HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.20

    System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.

  • CVE-2018-16130HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.19

    System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter.

  • CVE-2018-13023HigNov 27, 2018
    risk 0.59cvss 8.8epss 0.19

    System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter.

  • CVE-2018-15709HigNov 14, 2018
    risk 0.59cvss 8.8epss 0.12

    Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.