VYPR

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

BaseDraft

Description

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-137 · CAPEC-174 · CAPEC-41 · CAPEC-460 · CAPEC-88

CVEs mapped to this weakness (410)

page 5 of 21
  • CVE-2025-1712HigMay 21, 2025
    risk 0.57cvss 8.8epss 0.01

    Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files

  • CVE-2025-21613CriJan 6, 2025
    risk 0.57cvss 9.8epss 0.01

    go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack…

  • CVE-2024-2422HigMay 30, 2024
    risk 0.57cvss 8.8epss 0.01

    LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands.

  • CVE-2023-50232HigMay 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Inductive Automation Ignition getParams Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this…

  • CVE-2024-3817CriApr 17, 2024
    risk 0.57cvss 9.8epss 0.01

    HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

  • CVE-2024-23731CriJan 21, 2024
    risk 0.57cvss 9.8epss 0.01

    The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

  • CVE-2023-47804HigDec 29, 2023
    risk 0.57cvss 8.8epss 0.03

    Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. …

  • CVE-2023-25356HigApr 4, 2023
    risk 0.57cvss 8.8epss 0.02

    CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This…

  • CVE-2022-46883HigDec 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been…

  • CVE-2022-23740HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub…

  • CVE-2022-42968CriOct 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

  • CVE-2022-25168CriAug 4, 2022
    risk 0.57cvss 9.8epss 0.04

    Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It…

  • CVE-2022-24437CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.04

    The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to…

  • CVE-2022-1440CriApr 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Command Injection vulnerability in [email protected] in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow…

  • CVE-2022-28391HigApr 3, 2022
    risk 0.57cvss 8.8epss 0.03

    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

  • CVE-2021-36122HigJul 13, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the…

  • CVE-2020-25268HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.02

    Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

  • CVE-2020-7808HigMay 21, 2020
    risk 0.57cvss 8.7epss 0.01

    In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.

  • CVE-2020-5546HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop…

  • CVE-2020-6799HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.02

    Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party…