CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,257 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 5 of 126
- CVE-2014-3121HIGHCVSS v2 7.6EG 7.62014-05-14
rxvt-unicode before 9.20 does not properly handle OSC escape sequences, which allows user-assisted remote attackers to manipulate arbitrary X window properties and execute arbitrary commands.
- CVE-2014-3357HIGHCVSS v2 7.8EG 7.82014-09-25
Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets…
- CVE-2014-3358HIGHCVSS v2 7.8EG 7.82014-09-25
Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and i…
- CVE-2014-3360HIGHCVSS v2 7.8EG 7.82014-09-25
Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allow remote attackers to cause a denial of serv…
- CVE-2014-3418HIGHCVSS v2 10.0EG 10.02014-07-15
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.
- CVE-2014-3883MEDIUMCVSS v2 6.8EG 6.82014-06-21
Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.
- CVE-2014-4823HIGHCVSS v2 10.0EG 10.02014-10-03
The administration console in IBM Security Access Manager for Web 7.x before 7.0.0-ISS-WGA-IF0009 and 8.x before 8.0.0-ISS-WGA-FP0005, and Security Access Manager for Mobile 8.x before 8.0.0-ISS-ISAM-FP0005, allows remote attackers to inje…
- CVE-2014-4868HIGHCVSS v2 9.0EG 9.02014-10-07
The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.
- CVE-2014-4981CRITICALCVSS 9.8EG 9.82020-02-17
LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.
- CVE-2014-5502HIGHCVSS v2 9.0EG 9.02014-10-07
The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file op…
- CVE-2014-6271CRITICALCVSS 9.8EG 9.8⚠ KEV2014-09-24
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the …
- CVE-2014-6277HIGHCVSS v2 10.0EG 10.02014-09-27
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and unt…
- CVE-2014-6278CRITICALCVSS 8.8EG 9.0⚠ KEV2014-09-30
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involvin…
- CVE-2014-6434HIGHCVSS v2 10.0EG 10.02014-10-07
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.
- CVE-2014-7169CRITICALCVSS 9.8EG 9.8⚠ KEV2014-09-25
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a cra…
- CVE-2014-7173CRITICALCVSS 9.8EG 9.82020-06-01
FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php.
- CVE-2014-7253HIGHCVSS v2 7.2EG 7.22014-12-05
FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors.
- CVE-2014-7269MEDIUMCVSS v2 6.5EG 6.52015-02-01
ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.371…
- CVE-2014-8334MEDIUMCVSS v2 6.5EG 6.52014-10-31
The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup[…
- CVE-2014-8387HIGHCVSS v2 9.0EG 9.02014-11-20
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
- CVE-2014-8389CRITICALCVSS 9.8EG 9.82017-12-28
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirL…
- CVE-2014-8563CRITICALCVSS 9.8EG 9.82020-01-27
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
- CVE-2014-8945CRITICALCVSS 9.8EG 9.82020-06-01
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
- CVE-2015-0525HIGHCVSS v2 7.5EG 7.52015-03-12
The Gateway Provisioning service in EMC Secure Remote Services Virtual Edition (ESRS VE) 3.02 and 3.03 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2015-0977HIGHCVSS v2 10.0EG 10.02015-02-27
Network Vision IntraVue before 2.3.0a14 on Windows allows remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2015-10141CRITICALCVSS 9.3EG 9.32025-07-23
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugge…
- CVE-2015-10145HIGHCVSS 8.8EG 8.82025-12-31
Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, …
- CVE-2015-1388HIGHCVSS v2 7.2EG 7.22015-03-24
The "RAP console" feature in ArubaOS 5.x through 6.2.x, 6.3.x before 6.3.1.15, and 6.4.x before 6.4.2.4 on Aruba access points in Remote Access Point (AP) mode allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2015-2201HIGHCVSS 7.2EG 7.22023-09-05
Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.
- CVE-2015-2279CRITICALCVSS 9.8EG 9.82017-07-25
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac w…
- CVE-2015-2280HIGHCVSS 8.8EG 8.82017-07-25
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac param…
- CVE-2015-3431CRITICALCVSS 9.8EG 9.82017-09-19
Pydio (formerly AjaXplorer) before 6.0.7 allows remote attackers to execute arbitrary commands via unspecified vectors, aka "Pydio OS Command Injection Vulnerabilities."
- CVE-2015-3611HIGHCVSS 8.8EG 8.82020-02-04
A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could let a malicious user run systems commands when executing a report.
- CVE-2015-4117HIGHCVSS 8.8EG 8.82018-02-28
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
- CVE-2015-4642CRITICALCVSS 9.8EG 9.82016-05-16
The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts c…
- CVE-2015-4956HIGHCVSS 7.4EG 7.42016-02-15
The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.
- CVE-2015-5018HIGHCVSS 8.0EG 8.02016-01-02
IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interfa…
- CVE-2015-5958HIGHCVSS 8.8EG 8.82017-08-31
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
- CVE-2015-6396HIGHCVSS 7.8EG 7.82016-08-08
The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
- CVE-2015-6435CRITICALCVSS 9.8EG 9.82016-01-22
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary she…
- CVE-2015-7426CRITICALCVSS 10.0EG 10.02016-01-02
The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 7.1 before 7.1.3.0 and Tivoli Storage FlashCopy Manager for …
- CVE-2015-7611HIGHCVSS 8.1EG 8.72016-06-07
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.
- CVE-2015-7769MEDIUMCVSS 6.3EG 6.32016-02-19
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
- CVE-2015-8151CRITICALCVSS 9.1EG 9.12016-02-18
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.
- CVE-2015-8557CRITICALCVSS 9.0EG 9.02016-01-08
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
- CVE-2016-0291HIGHCVSS 8.8EG 8.82018-02-28
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
- CVE-2016-0325MEDIUMCVSS 6.3EG 6.32016-11-24
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iF…
- CVE-2016-0634HIGHCVSS 7.5EG 7.52017-08-28
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
- CVE-2016-1000216HIGHCVSS 8.8EG 8.82016-10-10
Ruckus Wireless H500 web management interface authenticated command injection
- CVE-2016-10043CRITICALCVSS 10.0EG 10.02017-01-31
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (|) to inject arbitr…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →