CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php...Show more |
Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie,...Show more |
1Proofpoint 2Messaging Security Gateway Protection ServerApr 29, 2026 May 5, 2011 N/A· v4 N/A· v3 7.5 HIGH· v2 An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers t...Show more |
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." |
1Cisco 2Telepresence Recording Server Telepresence Recording Server SoftwareApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulne...Show more |
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injecti...Show more |
1Cisco 7Telepresence System 1000 Telepresence System 1100Telepresence System 1300 Series+4 moreApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 8.3 HIGH· v2 The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability,"...Show more |
1Cisco 7Telepresence System 1000 Telepresence System 1100Telepresence System 1300 Series+4 moreApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 9.0 HIGH· v2 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulne...Show more |
1Cisco 7Telepresence System 1000 Telepresence System 1100Telepresence System 1300 Series+4 moreApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 9.0 HIGH· v2 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulne...Show more |
1Cisco 7Telepresence System 1000 Telepresence System 1100Telepresence System 1300 Series+4 moreApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 9.0 HIGH· v2 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulne...Show more |
1Cisco 7Telepresence System 1000 Telepresence System 1100Telepresence System 1300 Series+4 moreApr 29, 2026 Feb 25, 2011 N/A· v4 N/A· v3 10.0 HIGH· v2 The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities...Show more |
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this...Show more |
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to i...Show more |
1Cisco 1Unified Communications Manager Apr 29, 2026 Nov 9, 2010 N/A· v4 N/A· v3 6.8 MEDIUM· v2 /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters...Show more |
Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execut...Show more |
The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the con...Show more |
programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_banner (aka server_banner) field, a differen...Show more |
programs/pluto/xauth.c in the client in Openswan 2.6.25 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in (1) cisco_dns_info or (2) cisco_domain_info data in a...Show more |
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile,...Show more |
1Microsoft 3Windows 2003 Server Windows Server 2003Windows XpApr 29, 2026 Jun 15, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass th...Show more |