CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,259 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 19 of 126
- CVE-2019-10789CRITICALCVSS 9.8EG 9.82020-02-06
All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.
- CVE-2019-10791CRITICALCVSS 9.8EG 9.82020-02-18
promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.
- CVE-2019-10796CRITICALCVSS 9.8EG 9.82020-02-24
rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the arguement of exec function without any sanitization.
- CVE-2019-10799HIGHCVSS 8.2EG 8.22020-02-24
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.
- CVE-2019-10801CRITICALCVSS 9.8EG 9.82020-02-28
enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.
- CVE-2019-10802CRITICALCVSS 9.8EG 9.82020-02-28
giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is executed by the package without any validation.
- CVE-2019-10803CRITICALCVSS 9.8EG 9.82020-02-28
push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" is not validated before being provided to the "git" command within "index.js#L139". This could be abused by an attacker …
- CVE-2019-10804CRITICALCVSS 9.8EG 9.82020-02-28
serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is used by the "exec" function without any validation.
- CVE-2019-10807CRITICALCVSS 9.8EG 9.82020-03-11
Blamer versions prior to 1.0.1 allows execution of arbitrary commands. It is possible to inject arbitrary commands as part of the arguments provided to blamer.
- CVE-2019-10880CRITICALCVSS 9.8EG 9.82019-04-12
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configurat…
- CVE-2019-10883CRITICALCVSS 9.8EG 9.82019-06-03
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
- CVE-2019-10891CRITICALCVSS 9.8EG 9.82019-09-06
An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls system() without checking the parameter that can be controlled by user, and finally allows remote attackers to execute arbit…
- CVE-2019-10956HIGHCVSS 7.2EG 7.22020-01-17
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.
- CVE-2019-10958HIGHCVSS 7.2EG 7.22020-01-17
Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, …
- CVE-2019-11001CRITICALCVSS 7.2EG 9.0⚠ KEV2019-04-08
On Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W devices through 1.0.227, an authenticated admin can use the "TestEmail" functionality to inject and run OS commands as root, as demonstrated by shell metacharacters in the addr1 f…
- CVE-2019-11062CRITICALCVSS 9.8EG 9.82019-07-11
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
- CVE-2019-11224HIGHCVSS 8.8EG 8.82019-05-15
HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.
- CVE-2019-11319CRITICALCVSS 9.8EG 9.82019-04-18
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
- CVE-2019-11322CRITICALCVSS 9.8EG 9.82019-04-18
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
- CVE-2019-11353CRITICALCVSS 9.8EG 9.82019-05-09
The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed…
- CVE-2019-11355HIGHCVSS 7.2EG 7.22020-03-12
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user…
- CVE-2019-11364HIGHCVSS 7.2EG 7.22019-08-29
An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbitrary OS commands via the ServerConf/DataManagement/DiskManager.php FORMNAS_share parameter.
- CVE-2019-11399CRITICALCVSS 9.8EG 9.82019-12-18
An issue was discovered on TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices. OS command injection occurs through the get_set.ccp lanHostCfg_HostName_1.1.1.0.0 parameter.
- CVE-2019-11409CRITICALCVSS 8.8EG 9.02019-06-17
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the …
- CVE-2019-11410HIGHCVSS 7.2EG 7.22019-06-17
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.
- CVE-2019-11444HIGHCVSS 7.2EG 7.22019-04-22
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminP…
- CVE-2019-11527HIGHCVSS 8.8EG 8.82019-10-10
An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.
- CVE-2019-11539CRITICALCVSS 7.2EG 9.0⚠ KEV2019-04-26
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.…
- CVE-2019-11627CRITICALCVSS 9.8EG 9.82019-04-30
gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.
- CVE-2019-11689HIGHCVSS 8.1EG 8.12020-03-18
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exfatctl fail to properly validate server responses and pass unsanitized text to the system shell, resulting in code execu…
- CVE-2019-11829CRITICALCVSS 7.3EG 9.82019-06-30
OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.
- CVE-2019-12091HIGHCVSS 7.8EG 7.82019-09-26
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost. The connection handling function in this service suffers from command injection vul…
- CVE-2019-12103CRITICALCVSS 9.8EG 9.82019-08-14
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulnerability.
- CVE-2019-12112CRITICALCVSS 9.8EG 9.82020-03-18
An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
- CVE-2019-12113HIGHCVSS 8.8EG 8.82020-03-18
An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.
- CVE-2019-12123HIGHCVSS 8.8EG 8.82020-03-18
An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an authenticated user can execute an arbitrary command. All SDC setups that include admportal are affected.
- CVE-2019-12132CRITICALCVSS 9.8EG 9.82020-03-18
An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.
- CVE-2019-12181HIGHCVSS 8.8EG 8.92019-06-17
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
- CVE-2019-12272CRITICALCVSS 9.8EG 9.82019-05-23
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
- CVE-2019-12324HIGHCVSS 7.2EG 7.22019-07-22
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote attacker in the sa…
- CVE-2019-12328CRITICALCVSS 9.0EG 9.02019-07-22
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the same network to trigge…
- CVE-2019-12430HIGHCVSS 8.8EG 8.82020-03-10
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injec…
- CVE-2019-12489CRITICALCVSS 9.8EG 9.82019-11-26
An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_remove service through an HTTP request, it is possible to inject and execute a command between two & characters in the mo…
- CVE-2019-12511CRITICALCVSS 9.8EG 9.82020-02-24
In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although t…
- CVE-2019-12579HIGHCVSS 7.8EG 7.82019-07-11
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_laun…
- CVE-2019-12585CRITICALCVSS 9.8EG 9.82019-06-03
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
- CVE-2019-12629HIGHCVSS 7.2EG 7.22020-01-26
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient i…
- CVE-2019-12650HIGHCVSS 8.8EG 8.82019-09-25
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these …
- CVE-2019-12651HIGHCVSS 8.8EG 8.82019-09-25
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these …
- CVE-2019-12661MEDIUMCVSS 6.7EG 6.72019-09-25
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of r…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →