CWE-78
5,949 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,949)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Onap 1Open Network Automation Platform Nov 21, 2024 Mar 18, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected. |
1Onap 1Open Network Automation Platform Nov 21, 2024 Mar 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affec...Show more |
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resu...Show more |
1Swisscom 1Centro Grande Firmware Nov 21, 2024 Mar 16, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection. |
1Fortinet 4Fortiap Fortiap SFortiap U+1 moreNov 21, 2024 Mar 15, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under CLI admin console may allow unauthorized administrators to run arbitrary...Show more |
1Gulp Styledocco Project 1Gulp Styledocco Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gulp-styledocco through 0.0.3 allows execution of arbitrary commands. The argument 'options' of the exports function in 'index.js' can be controlled by users without any sanitization. |
1Docker Compose Remote Api Project 1Docker Compose Remote Api Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which ca...Show more |
1Gulp Tape Project 1Gulp Tape Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gulp-tape through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of 'gulp-tape' options. |
1Pulverizr Project 1Pulverizr Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the...Show more |
1Closure Compiler Stream Project 1Closure Compiler Stream Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 closure-compiler-stream through 0.1.15 allows execution of arbitrary commands. The argument "options" of the exports function in "index.js" can be controlled by users without any sanitization. |
1Node Prompt Here Project 1Node Prompt Here Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 node-prompt-here through 1.0.1 allows execution of arbitrary commands. The "runCommand()" is called by "getDevices()" function in file "linux/manager.js", which is required by the "index. process.env.NM_CLI" in the file...Show more |
1Gulp Scss Lint Project 1Gulp Scss Lint Nov 21, 2024 Mar 15, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gulp-scss-lint through 1.0.0 allows execution of arbitrary commands. It is possible to inject arbitrary commands to the "exec" function located in "src/command.js" via the provided options. |
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value rec...Show more |
1Phoenixcontact 6Tc Cloud Client 1002 4g Firmware Tc Cloud Client 1002 Txtx FirmwareTc Router 2002t 3g Firmware+3 moreNov 21, 2024 Mar 12, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CL...Show more |
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be exec...Show more |
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send specially crafted packet at 0x1ea48 to the extrac...Show more |
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on t...Show more |
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on t...Show more |
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on t...Show more |
An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device...Show more |