CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,224 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 2 of 85
- CVE-2014-8630MEDIUMCVSS v2 6.5EG 6.52015-02-01
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted in…
- CVE-2014-8888CRITICALCVSS 9.8EG 9.82018-04-12
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection issue."
- CVE-2014-8903HIGHCVSS 8.8EG 8.82017-08-02
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
- CVE-2014-8990HIGHCVSS v2 7.5EG 7.52014-12-05
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
- CVE-2014-9114HIGHCVSS 7.8EG 7.82017-03-31
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
- CVE-2014-9118HIGHCVSS 8.8EG 8.92017-10-17
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
- CVE-2014-9144HIGHCVSS v2 7.5EG 7.52014-12-05
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).
- CVE-2014-9188HIGHCVSS v2 9.0EG 9.02014-12-27
Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NO…
- CVE-2014-9277HIGHCVSS v2 7.5EG 7.52015-01-04
The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injection attacks via a crafted string containi…
- CVE-2014-9622MEDIUMCVSS v2 6.8EG 6.82015-01-21
Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.
- CVE-2015-0778HIGHCVSS v2 7.5EG 7.52015-03-16
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
- CVE-2015-0857CRITICALCVSS 9.8EG 9.82016-05-06
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
- CVE-2015-0934MEDIUMCVSS v2 6.5EG 6.52015-03-04
Common LaTeX Service Interface (CLSI) before 0.1.3, as used in ShareLaTeX before 0.1.3, allows remote authenticated users to execute arbitrary code via ` (backtick) characters in a filename.
- CVE-2015-10096CRITICALCVSS 5.0EG 9.82023-03-20
A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affects the function get_tweets of the file lib/twitterbot/plugins/twitter_announcer.rb. The manipulation of the argument t…
- CVE-2015-1815HIGHCVSS v2 10.0EG 10.02015-03-30
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
- CVE-2015-1877HIGHCVSS 8.8EG 8.82021-06-02
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
- CVE-2015-20107CRITICALCVSS 7.6EG 9.82022-04-13
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch wi…
- CVE-2015-20108CRITICALCVSS 9.8EG 9.82023-05-27
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.
- CVE-2015-2051CRITICALCVSS 8.8EG 9.0⚠ KEV2015-02-23
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
- CVE-2015-2208HIGHCVSS v2 7.5EG 7.52015-03-12
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the object parameter.
- CVE-2015-2210HIGHCVSS 7.8EG 7.82017-09-06
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command shell.
- CVE-2015-2265HIGHCVSS v2 7.5EG 7.52015-03-24
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists …
- CVE-2015-2746MEDIUMCVSS v2 6.5EG 6.52015-03-26
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands v…
- CVE-2015-2857CRITICALCVSS 9.8EG 9.82017-08-22
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
- CVE-2015-3441HIGHCVSS 8.8EG 8.82017-01-05
The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbitrary CLI commands via the (1) start_hour, (2) start_minute, (3) end_hour, (4) end_minute, or (5) hostname parameter.
- CVE-2015-4046HIGHCVSS 7.2EG 7.22017-05-23
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
- CVE-2015-4852CRITICALCVSS 9.8EG 9.8⚠ KEV2015-11-18
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to …
- CVE-2015-5003HIGHCVSS 8.5EG 8.52016-01-03
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.
- CVE-2015-5349HIGHCVSS 7.8EG 7.82016-04-11
The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a …
- CVE-2015-5704HIGHCVSS 7.8EG 7.82017-09-25
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
- CVE-2015-6024CRITICALCVSS 9.8EG 9.82017-02-09
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter.
- CVE-2015-6971HIGHCVSS 7.8EG 7.82017-10-03
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
- CVE-2015-7541CRITICALCVSS 10.0EG 10.02016-01-08
The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors…
- CVE-2015-7806CRITICALCVSS 9.8EG 9.82017-10-17
Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2015-7841CRITICALCVSS 9.8EG 9.82017-10-03
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software …
- CVE-2015-8257HIGHCVSS 8.8EG 8.82017-05-02
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4…
- CVE-2015-8968HIGHCVSS 8.8EG 8.82016-11-03
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alt…
- CVE-2015-8969CRITICALCVSS 9.8EG 9.82016-11-03
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.
- CVE-2015-8971HIGHCVSS 7.8EG 7.82017-01-23
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.
- CVE-2015-8988HIGHCVSS 8.8EG 8.82017-03-14
Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 allows authenticated users to execute a command of their choice via dropping a malicious f…
- CVE-2015-9059CRITICALCVSS 9.8EG 9.82017-05-28
picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
- CVE-2016-0236HIGHCVSS 8.8EG 8.82016-10-21
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field.
- CVE-2016-0324HIGHCVSS 8.8EG 8.82018-01-12
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 1…
- CVE-2016-0326HIGHCVSS 8.8EG 8.82016-10-22
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS …
- CVE-2016-0328HIGHCVSS 7.8EG 7.82016-10-22
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.
- CVE-2016-0396HIGHCVSS 8.1EG 8.12017-02-01
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
- CVE-2016-0861HIGHCVSS 8.8EG 8.82016-02-05
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.
- CVE-2016-0920HIGHCVSS 7.8EG 7.82016-09-21
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.
- CVE-2016-1000156CRITICALCVSS 9.8EG 9.82016-12-14
Mailcwp remote file upload vulnerability incomplete fix v1.100
- CVE-2016-1000282CRITICALCVSS 9.8EG 9.82019-02-05
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →