Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-07-02 CVE-2018-1244 Command Injection vulnerability in Dell Idrac7 Firmware, Idrac8 Firmware and Idrac9 Firmware
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent.
network
low complexity
dell CWE-77
8.8
2018-07-02 CVE-2018-1212 Command Injection vulnerability in Dell Idrac6 Modular and Idrac6 Monolithic
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability.
network
low complexity
dell CWE-77
8.8
2018-06-21 CVE-2018-0712 Command Injection vulnerability in Qnap QTS
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.
network
low complexity
qnap CWE-77
critical
9.8
2018-06-20 CVE-2018-5428 Command Injection vulnerability in Tibco Data Virtualization 7.0.5/7.0.6
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution.
network
low complexity
tibco CWE-77
8.8
2018-06-08 CVE-2014-5220 Command Injection vulnerability in multiple products
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
local
low complexity
opensuse mdadm-project CWE-77
7.8
2018-06-08 CVE-2017-12078 Command Injection vulnerability in Synology Router Manager
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter.
network
low complexity
synology CWE-77
7.2
2018-06-08 CVE-2017-12075 Command Injection vulnerability in Synology Diskstation Manager
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
network
low complexity
synology CWE-77
7.2
2018-06-07 CVE-2017-16100 Command Injection vulnerability in Dns-Sync Project Dns-Sync 0.1.0/0.1.1
dns-sync is a sync/blocking dns resolver.
network
low complexity
dns-sync-project CWE-77
critical
9.8
2018-05-29 CVE-2016-7076 Command Injection vulnerability in Sudo Project Sudo
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument.
local
low complexity
sudo-project CWE-77
7.8
2018-04-25 CVE-2014-5014 Command Injection vulnerability in Tinywebgallery Wordpress Flash Uploader
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
network
low complexity
tinywebgallery CWE-77
critical
9.8