CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,257 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 6 of 126
- CVE-2016-10320HIGHCVSS 7.8EG 7.82017-04-06
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
- CVE-2016-10541CRITICALCVSS 9.8EG 9.82018-05-31
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
- CVE-2016-10709HIGHCVSS 8.8EG 8.82018-01-22
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.
- CVE-2016-11017CRITICALCVSS 9.8EG 9.82020-01-06
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command…
- CVE-2016-11021CRITICALCVSS 7.2EG 9.0⚠ KEV2020-03-09
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
- CVE-2016-11022HIGHCVSS 7.2EG 7.22020-03-23
NETGEAR Prosafe WC9500 5.1.0.17, WC7600 5.1.0.17, and WC7520 2.5.0.35 devices allow a remote attacker to execute code with root privileges via shell metacharacters in the reqMethod parameter to login_handler.php.
- CVE-2016-11054HIGHCVSS 7.2EG 7.22020-04-28
NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.
- CVE-2016-11061CRITICALCVSS 9.8EG 9.82020-04-29
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow…
- CVE-2016-1141MEDIUMCVSS 4.7EG 4.72016-01-30
KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.
- CVE-2016-1142CRITICALCVSS 9.1EG 9.12016-01-16
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
- CVE-2016-1253CRITICALCVSS 9.8EG 9.82017-12-05
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the name of an LZMA-co…
- CVE-2016-1297HIGHCVSS 8.8EG 8.82016-02-26
The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified para…
- CVE-2016-1320MEDIUMCVSS 6.7EG 6.72016-02-12
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
- CVE-2016-1339HIGHCVSS 7.8EG 7.82016-04-16
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.
- CVE-2016-1352CRITICALCVSS 9.8EG 9.82016-04-14
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.
- CVE-2016-1468HIGHCVSS 8.8EG 8.82016-08-08
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
- CVE-2016-1482HIGHCVSS 8.1EG 8.12016-09-17
Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.
- CVE-2016-15047HIGHCVSS 8.7EG 8.72025-10-09
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validati…
- CVE-2016-15048CRITICALCVSS 9.8EG 9.82025-10-22
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpoint. The application constructs a shell command that includes the user-supplied ip parame…
- CVE-2016-20016CRITICALCVSS 9.8EG 9.82022-10-19
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerabilit…
- CVE-2016-2876HIGHCVSS 7.5EG 7.52016-11-30
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.
- CVE-2016-3028CRITICALCVSS 9.1EG 9.12016-11-25
IBM Security Access Manager for Web 7.0 before IF2 and 8.0 before 8.0.1.4 IF3 and Security Access Manager 9.0 before 9.0.1.0 IF5 allow remote authenticated users to execute arbitrary commands by leveraging LMI admin access.
- CVE-2016-3655CRITICALCVSS 9.8EG 9.82016-04-12
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.
- CVE-2016-4853HIGHCVSS 7.8EG 7.82016-09-02
AKABEi SOFT2 games allow remote attackers to execute arbitrary OS commands via crafted saved data, as demonstrated by Happy Wardrobe.
- CVE-2016-4965HIGHCVSS 8.8EG 8.82016-09-21
Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.
- CVE-2016-5313HIGHCVSS 8.8EG 8.82017-04-12
Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
- CVE-2016-5679HIGHCVSS 8.8EG 8.82016-08-31
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command.
- CVE-2016-6065HIGHCVSS 7.8EG 7.82017-02-01
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
- CVE-2016-6147CRITICALCVSS 9.8EG 9.82016-08-05
An unspecified interface in SAP TREX 7.10 Revision 63 allows remote attackers to execute arbitrary OS commands with SIDadm privileges via unspecified vectors, aka SAP Security Note 2234226.
- CVE-2016-6373HIGHCVSS 7.2EG 7.22016-09-22
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.
- CVE-2016-6414HIGHCVSS 7.8EG 7.82016-09-22
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
- CVE-2016-6459MEDIUMCVSS 5.5EG 5.52016-11-19
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.…
- CVE-2016-6631HIGHCVSS 7.5EG 7.52016-12-11
An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmin is being run as a CGI application. Under certain server configurations, a user can pass a query string which is execu…
- CVE-2016-7806CRITICALCVSS 9.8EG 9.82017-06-09
I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.
- CVE-2016-7819HIGHCVSS 7.2EG 7.22017-06-09
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
- CVE-2016-7844MEDIUMCVSS 5.5EG 5.52017-08-02
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.
- CVE-2016-8721CRITICALCVSS 9.1EG 9.12017-04-20
An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resultin…
- CVE-2016-9091HIGHCVSS 7.2EG 7.22017-04-05
Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS com…
- CVE-2017-1000009CRITICALCVSS 9.8EG 9.82017-07-17
Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
- CVE-2017-1000116CRITICALCVSS 9.8EG 9.82017-10-05
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
- CVE-2017-1000159HIGHCVSS 7.8EG 7.82017-11-27
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.
- CVE-2017-1000203HIGHCVSS 8.8EG 8.82017-11-17
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution
- CVE-2017-1000214CRITICALCVSS 9.8EG 9.82017-11-27
GitPHP by xiphux is vulnerable to OS Command Injections
- CVE-2017-1000215CRITICALCVSS 9.8EG 9.82017-11-17
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
- CVE-2017-1000219CRITICALCVSS 9.8EG 9.82017-11-17
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
- CVE-2017-1000220CRITICALCVSS 9.8EG 9.82017-11-17
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution
- CVE-2017-1000235CRITICALCVSS 9.8EG 9.82017-11-17
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
- CVE-2017-1000393HIGHCVSS 8.8EG 8.82018-01-26
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'. This allowed them to run arbitrary shell …
- CVE-2017-1000473HIGHCVSS 7.8EG 7.82018-01-03
Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root.
- CVE-2017-1000487CRITICALCVSS 9.8EG 9.82018-01-03
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →