CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 4 of 83
- CVE-2016-8628HIGHCVSS 7.6EG 7.62018-07-31
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the …
- CVE-2016-8801HIGHCVSS 7.2EG 7.22017-04-02
Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific command's parameters, and run this injected command with root privilege.
- CVE-2016-9044HIGHCVSS 8.8EG 8.82018-09-07
An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web parameter can cause a command injection. An authenticated attacker can send a crafted web req…
- CVE-2016-9337MEDIUMCVSS 6.8EG 6.82017-02-13
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to commands that may allow an attacker to insta…
- CVE-2016-9553HIGHCVSS 7.2EG 7.22017-01-28
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component re…
- CVE-2016-9554HIGHCVSS 7.2EG 7.22017-01-28
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controller…
- CVE-2016-9682CRITICALCVSS 9.8EG 9.82017-02-22
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) c…
- CVE-2016-9683CRITICALCVSS 9.8EG 9.82017-02-22
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionset…
- CVE-2016-9684CRITICALCVSS 9.8EG 9.82017-02-22
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component r…
- CVE-2016-9835CRITICALCVSS 9.8EG 9.82016-12-05
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
- CVE-2016-9873MEDIUMCVSS 6.3EG 6.32017-02-03
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could pote…
- CVE-2017-0915CRITICALCVSS 9.8EG 9.82018-03-21
Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.
- CVE-2017-0916CRITICALCVSS 9.8EG 9.82018-03-21
Gitlab Community Edition version 10.3 is vulnerable to a lack of input validation in the system_hook_push queue through web hook component resulting in remote code execution.
- CVE-2017-11391HIGHCVSS 8.8EG 8.92017-08-03
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" par…
- CVE-2017-11392HIGHCVSS 8.8EG 8.82017-08-03
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" par…
- CVE-2017-12075HIGHCVSS 7.2EG 7.22018-06-08
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
- CVE-2017-12078HIGHCVSS 7.2EG 7.22018-06-08
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter.
- CVE-2017-12094HIGHCVSS 6.5EG 7.42017-11-07
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reach…
- CVE-2017-12277HIGHCVSS 8.8EG 8.82017-11-02
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that…
- CVE-2017-12305MEDIUMCVSS 6.7EG 6.72017-11-16
A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. …
- CVE-2017-12329MEDIUMCVSS 6.3EG 6.32017-11-30
A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input v…
- CVE-2017-12330MEDIUMCVSS 6.3EG 6.32017-11-30
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser.…
- CVE-2017-12335MEDIUMCVSS 6.3EG 6.32017-11-30
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could…
- CVE-2017-12339MEDIUMCVSS 5.7EG 5.72017-11-30
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser.…
- CVE-2017-12341MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability…
- CVE-2017-12352MEDIUMCVSS 6.7EG 6.72017-11-30
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands w…
- CVE-2017-12756HIGHCVSS 7.2EG 7.22017-08-09
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.
- CVE-2017-13069CRITICALCVSS 9.8EG 9.82017-10-06
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary comma…
- CVE-2017-13071CRITICALCVSS 9.8EG 9.82017-11-22
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on the QNAP Video Station 5.1.3 (for QTS 4.3.3), 5.2.0 (for QTS 4.3.4), and earlier.
- CVE-2017-1352MEDIUMCVSS 5.5EG 5.52017-09-12
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
- CVE-2017-1407HIGHCVSS 8.8EG 8.82017-09-28
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to ex…
- CVE-2017-14081HIGHCVSS 8.8EG 8.82017-09-22
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
- CVE-2017-14592HIGHCVSS 8.8EG 8.82018-01-26
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code …
- CVE-2017-14593HIGHCVSS 8.8EG 8.82018-01-26
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain c…
- CVE-2017-15403HIGHCVSS 7.3EG 7.32019-01-09
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a crafted HTML page.
- CVE-2017-15889CRITICALCVSS 8.8EG 9.02017-12-04
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
- CVE-2017-15940CRITICALCVSS 9.8EG 9.82017-12-11
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified …
- CVE-2017-16100CRITICALCVSS 9.8EG 9.82018-06-07
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
- CVE-2017-1720MEDIUMCVSS 5.3EG 5.32018-02-13
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.
- CVE-2017-18377CRITICALCVSS 9.8EG 9.82019-06-11
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.
- CVE-2017-18378CRITICALCVSS 8.4EG 9.82019-06-11
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=writeuploaddir remote command execution.
- CVE-2017-18400HIGHCVSS 7.8EG 7.82019-08-02
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
- CVE-2017-18442MEDIUMCVSS 5.3EG 5.32019-08-02
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
- CVE-2017-20156CRITICALCVSS 5.5EG 9.82022-12-31
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of the file lib/printer/jobs/prepare_page.rb of the component Argument Handler. The manipulation of the argument URL leads…
- CVE-2017-2324MEDIUMCVSS 5.3EG 5.32017-04-24
A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.
- CVE-2017-2349CRITICALCVSS 8.8EG 9.92017-07-17
A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access to the device to execute shell commands and elevate privileges. Affected releases are Junip…
- CVE-2017-2692HIGHCVSS 7.8EG 7.82017-11-22
The Keyguard application in ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier…
- CVE-2017-2718HIGHCVSS 8.8EG 8.82017-11-22
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by send…
- CVE-2017-2719HIGHCVSS 8.8EG 8.82017-11-22
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by send…
- CVE-2017-2736HIGHCVSS 7.2EG 7.22017-11-22
VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →