← Back
CWE-78

6,642 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,642)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Bsdi
CalderaIsc+3 more
7Bsd Os
Goah IntrasvGoah Networksv+4 more
Apr 16, 2026
Dec 4, 1996
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
2Apache
Ncsa
2Http Server
Ncsa Httpd
Apr 16, 2026
Mar 20, 1996
N/A· v4
N/A· v3
10.0 HIGH· v2
phf CGI program allows remote command execution through shell metacharacters.