CWE-78
5,949 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. |
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. |
Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call (aka Command Line Injection), if the undocumented telnetd service is enabled and the attacker can au...Show more |
Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service n...Show more |
1Netgear 2Wac505 Firmware Wac510 FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. |
1Netgear 2Wac505 Firmware Wac510 FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. |
1Netgear 2Wac505 Firmware Wac510 FirmwareNov 21, 2024 Apr 22, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17. |
1Evenroute 1Iqrouter Firmware Nov 21, 2024 Apr 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur...Show more |
1Dell 1Emc Integrated Data Protection Appliance Nov 21, 2024 Apr 15, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject param...Show more |
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted...Show more |
An issue was discovered in Rubrik 5.0.3-2296. An OS command injection vulnerability allows an authenticated attacker to remotely execute arbitrary code on Rubrik-managed systems. |
D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execute OS commands by placing shell metacharacters after a supported CLI command, as demonstrated by ping -c1 127.0.0.1; cat/etc/passwd. The CLI is reachable by TEL...Show more |
WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely. |
fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary commands. |
1Npm Programmatic Project 1Npm Programmatic Nov 21, 2024 Apr 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly. |
clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability req...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureNov 21, 2024 Apr 6, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-mid...Show more |
1Adb Driver Project 1Adb Driver Nov 21, 2024 Apr 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function. |
1Compass Compile Project 1Compass Compile Nov 21, 2024 Apr 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument. |
1Heroku Addonpool Project 1Heroku Addonpool Nov 21, 2024 Apr 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 heroku-addonpool through 0.1.15 is vulnerable to Command Injection. |