VYPR

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

BaseDraft

Description

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-137 · CAPEC-174 · CAPEC-41 · CAPEC-460 · CAPEC-88

CVEs mapped to this weakness (466)

page 6 of 24
  • CVE-2022-23740HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub…

  • CVE-2022-42968CriOct 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

  • CVE-2022-25168CriAug 4, 2022
    risk 0.57cvss 9.8epss 0.04

    Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It…

  • CVE-2022-24437CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.04

    The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to…

  • CVE-2022-1440CriApr 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Command Injection vulnerability in [email protected] in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow…

  • CVE-2022-28391HigApr 3, 2022
    risk 0.57cvss 8.8epss 0.03

    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

  • CVE-2021-36122HigJul 13, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from an authenticated user, leading to the…

  • CVE-2020-25268HigNov 10, 2020
    risk 0.57cvss 8.8epss 0.02

    Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

  • CVE-2020-7808HigMay 21, 2020
    risk 0.57cvss 8.7epss 0.01

    In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.

  • CVE-2020-5546HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop…

  • CVE-2020-6799HigMar 2, 2020
    risk 0.57cvss 8.8epss 0.02

    Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party…

  • CVE-2019-11751HigSep 27, 2019
    risk 0.57cvss 8.8epss 0.01

    Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup'…

  • CVE-2019-10746CriAug 23, 2019
    risk 0.57cvss 9.8epss 0.04

    mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

  • CVE-2019-15498HigAug 23, 2019
    risk 0.57cvss 8.8epss 0.03

    cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.

  • CVE-2018-0345HigJul 18, 2018
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected software. The…

  • CVE-2017-1001003CriNov 27, 2017
    risk 0.57cvss 9.8epss 0.02

    math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.

  • CVE-2026-8044HigSep 9, 2026
    risk 0.56cvss —epss 0.00

    CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.

  • CVE-2025-47421HigSep 3, 2025
    risk 0.56cvss —epss 0.00

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A specially crafted SCP command sent via SSH…

  • CVE-2024-22182HigMar 1, 2024
    risk 0.56cvss 8.6epss 0.01

    A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM causing the system to restart, interrupting service.

  • CVE-2025-43730HigAug 27, 2025
    risk 0.55cvss 8.4epss 0.00

    Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and…