CWE-78
6,645 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,645)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pyconuk 1Conference Scheduler Cli Nov 21, 2024 Aug 28, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call. |
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of...Show more |
Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allows a remote attacker to execute arbitrary OS commands via service parameters, such as shell metachar...Show more |
1Plainview Activity Monitor Project 1Plainview Activity Monitor Nov 21, 2024 Aug 26, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_...Show more |
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument. |
1Ucopia 1Wireless Appliance Firmware Nov 21, 2024 Aug 21, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.13 allows authenticated remote attackers to escape the shell and escalat...Show more |
1Telus 1Actiontec T2200h Firmware Nov 21, 2024 Aug 20, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field. |
1Git Dummy Commit Project 1Git Dummy Commit Nov 21, 2024 Aug 17, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A command injection in git-dummy-commit v1.3.0 allows os level commands to be executed due to an unescaped parameter. |
1Cisco 1Application Policy Infrastructure Controller Enterprise Module Nov 21, 2024 Aug 15, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect i...Show more |
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after modifying the "hylafax...Show more |
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the...Show more |
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying...Show more |
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the...Show more |
1Sony 14Snc Eb600 Firmware Snc Eb600b FirmwareSnc Eb602r Firmware+11 moreNov 21, 2024 Aug 14, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to...Show more |
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. |
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allow...Show more |
1Ocsinventory Ng 1Ocsinventory Ng Nov 21, 2024 Aug 4, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() cal...Show more |
2Debian Gnome2Debian Linux Network Manager VpncNov 21, 2024 Jul 26, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration dat...Show more |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a...Show more |
1Cisco 12Vbond Orchestrator Vedge 1000 FirmwareVedge 100 Firmware+9 moreNov 21, 2024 Jul 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input...Show more |