CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,259 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 22 of 126
- CVE-2019-1591HIGHCVSS 7.8EG 7.82019-03-06
A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insuf…
- CVE-2019-15949CRITICALCVSS 8.8EG 9.0⚠ KEV2019-09-05
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system prof…
- CVE-2019-15978HIGHCVSS 7.2EG 7.42020-01-06
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on th…
- CVE-2019-15979HIGHCVSS 7.2EG 7.22020-01-06
Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbitrary commands on th…
- CVE-2019-15986MEDIUMCVSS 6.7EG 6.72019-11-26
A vulnerability in the CLI of Cisco Unity Express could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. To exploit this vulnerability, an attacker would need valid administrator c…
- CVE-2019-15996MEDIUMCVSS 6.7EG 6.72019-11-26
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restricti…
- CVE-2019-15997MEDIUMCVSS 6.7EG 6.72019-11-26
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insuff…
- CVE-2019-16057CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-16
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
- CVE-2019-16072CRITICALCVSS 9.8EG 9.82020-03-20
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address var…
- CVE-2019-1612MEDIUMCVSS 4.2EG 6.72019-03-11
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1614HIGHCVSS 8.8EG 8.82019-03-11
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to incorrect input validation of user-supplied data by…
- CVE-2019-16213HIGHCVSS 8.8EG 8.82020-06-25
Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted string, an attacker could modify the device name of an attached PLC adapter…
- CVE-2019-1623MEDIUMCVSS 6.7EG 6.72019-06-20
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the executi…
- CVE-2019-16242MEDIUMCVSS 6.8EG 6.82019-11-26
On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to OS command injection. An attacker with physical access to the device can abuse this vulnerability to execute arbitrary …
- CVE-2019-1627MEDIUMCVSS 6.5EG 6.52019-06-20
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on t…
- CVE-2019-16293HIGHCVSS 8.8EG 8.82019-09-13
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
- CVE-2019-1634HIGHCVSS 7.2EG 7.22019-08-21
A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges on th…
- CVE-2019-1636HIGHCVSS 7.8EG 8.22019-01-23
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined…
- CVE-2019-1650HIGHCVSS 8.8EG 8.82019-01-24
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the …
- CVE-2019-1652CRITICALCVSS 7.2EG 9.0⚠ KEV2019-01-24
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitr…
- CVE-2019-16639CRITICALCVSS 9.8EG 9.82024-07-16
An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the…
- CVE-2019-16662CRITICALCVSS 9.8EG 9.82019-10-28
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can le…
- CVE-2019-16663CRITICALCVSS 8.8EG 9.02019-10-28
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, which can lead to com…
- CVE-2019-16701HIGHCVSS 8.8EG 8.82019-09-25
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
- CVE-2019-16718HIGHCVSS 7.8EG 7.82019-09-23
In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerab…
- CVE-2019-16730CRITICALCVSS 9.8EG 9.82019-12-13
processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2019-16733CRITICALCVSS 9.8EG 9.82019-12-13
processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2019-16737CRITICALCVSS 9.8EG 9.82019-12-13
The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2019-1674HIGHCVSS 7.8EG 8.82019-02-28
A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is …
- CVE-2019-16790MEDIUMCVSS 6.5EG 6.52019-12-30
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
- CVE-2019-16920CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-27
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead …
- CVE-2019-16964HIGHCVSS 8.8EG 8.82019-10-21
app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated attackers (with at least the permission call_cen…
- CVE-2019-16965HIGHCVSS 7.2EG 7.22019-10-21
resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute any commands on the host as www-data.
- CVE-2019-1699HIGHCVSS 6.7EG 7.82019-05-03
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could ex…
- CVE-2019-17059CRITICALCVSS 9.8EG 9.82019-10-11
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.
- CVE-2019-1709HIGHCVSS 6.0EG 7.82019-05-03
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could ex…
- CVE-2019-17095CRITICALCVSS 8.1EG 9.82020-01-27
A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote serve…
- CVE-2019-17096CRITICALCVSS 9.0EG 9.82020-01-27
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.
- CVE-2019-17107HIGHCVSS 8.8EG 8.82019-10-08
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.
- CVE-2019-17148HIGHCVSS 7.8EG 7.82020-01-07
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the targe…
- CVE-2019-1725MEDIUMCVSS 5.5EG 5.52019-04-18
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. It is also possible the attacker …
- CVE-2019-1726HIGHCVSS 7.8EG 7.82019-05-15
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to access internal services that should be restricted on an affected device, such as the NX-API. The vulnerability is due to insufficient valid…
- CVE-2019-17269CRITICALCVSS 9.8EG 9.82019-10-07
Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.
- CVE-2019-1727MEDIUMCVSS 6.7EG 6.72019-05-15
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level. The vulnerability is…
- CVE-2019-17270CRITICALCVSS 9.8EG 9.82019-12-10
Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the …
- CVE-2019-1732MEDIUMCVSS 6.4EG 6.42019-05-15
A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt l…
- CVE-2019-17364CRITICALCVSS 9.8EG 9.82019-12-13
The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.
- CVE-2019-1745HIGHCVSS 7.8EG 7.82019-03-28
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied b…
- CVE-2019-17499HIGHCVSS 8.8EG 8.82019-10-11
The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly validate ping command arguments, which allows remote authenticated users to execute OS commands as root via shell metachar…
- CVE-2019-17501HIGHCVSS 8.8EG 8.82019-10-14
Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Commands > Discovery screen). CVE-2019-17501 and CVE-2019-16405 are similar to one another and …
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →