CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,257 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 12 of 126
- CVE-2018-10697HIGHCVSS 8.8EG 8.82019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an at…
- CVE-2018-10699HIGHCVSS 8.8EG 8.82019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wireless network. However, the same functiona…
- CVE-2018-10702HIGHCVSS 8.8EG 8.82019-06-07
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the same functionality allows an attacker to execute commands on t…
- CVE-2018-10730CRITICALCVSS 9.1EG 9.12018-05-17
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to OS command injection.
- CVE-2018-10823CRITICALCVSS 8.8EG 9.02018-10-17
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injec…
- CVE-2018-10900HIGHCVSS 7.8EG 7.82018-07-26
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, a…
- CVE-2018-10905HIGHCVSS 7.8EG 7.82018-07-24
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms. An attacker with access to an unprivileged local shell could use this flaw to execute commands as a high privileged use…
- CVE-2018-10967HIGHCVSS 8.8EG 8.82018-05-18
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.
- CVE-2018-10987HIGHCVSS 7.5EG 7.52018-07-05
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated remote code execution vulnerability. An authenticated attacker can send a specially crafted UDP packet, and execute comma…
- CVE-2018-11077MEDIUMCVSS 6.7EG 6.72018-11-26
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 is affected by an OS command injection …
- CVE-2018-1111CRITICALCVSS 7.5EG 9.02018-05-17
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local…
- CVE-2018-11132HIGHCVSS 8.8EG 8.82018-05-31
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be executed. A command …
- CVE-2018-11138CRITICALCVSS 9.8EG 9.8⚠ KEV2018-05-31
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
- CVE-2018-11139HIGHCVSS 8.8EG 8.82018-05-31
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to c…
- CVE-2018-11143CRITICALCVSS 9.8EG 9.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
- CVE-2018-11144HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).
- CVE-2018-11145HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).
- CVE-2018-11146HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).
- CVE-2018-11147HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).
- CVE-2018-11148HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).
- CVE-2018-11149HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).
- CVE-2018-11150HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).
- CVE-2018-11151HIGHCVSS 7.2EG 7.22018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46).
- CVE-2018-11152HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).
- CVE-2018-11153HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).
- CVE-2018-11154HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).
- CVE-2018-11155HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).
- CVE-2018-11156HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46).
- CVE-2018-11157HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46).
- CVE-2018-11158HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46).
- CVE-2018-11159HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46).
- CVE-2018-11160HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46).
- CVE-2018-11161HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 19 of 46).
- CVE-2018-11162HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 20 of 46).
- CVE-2018-11163HIGHCVSS 7.2EG 7.22018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 21 of 46).
- CVE-2018-11164HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 22 of 46).
- CVE-2018-11165HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 23 of 46).
- CVE-2018-11166HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 24 of 46).
- CVE-2018-11167HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 25 of 46).
- CVE-2018-11168HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 26 of 46).
- CVE-2018-11169HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 27 of 46).
- CVE-2018-11170HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 28 of 46).
- CVE-2018-11171HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 29 of 46).
- CVE-2018-11172HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 30 of 46).
- CVE-2018-11173HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46).
- CVE-2018-11174HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 32 of 46).
- CVE-2018-11175HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).
- CVE-2018-11176HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46).
- CVE-2018-11177HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46).
- CVE-2018-11178HIGHCVSS 8.8EG 8.82018-06-02
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46).
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →