Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-01-03 CVE-2016-10107 Command Injection vulnerability in Western Digital Mycloud NAS 2.11.142
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
network
low complexity
western-digital CWE-77
critical
10.0
2016-12-30 CVE-2016-10074 Command Injection vulnerability in Swiftmailer
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
network
low complexity
swiftmailer CWE-77
7.5
2016-12-30 CVE-2016-10045 Command Injection vulnerability in multiple products
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP.
network
low complexity
phpmailer-project wordpress joomla CWE-77
7.5
2016-12-30 CVE-2016-10034 Command Injection vulnerability in Zend Zend-Mail and Zend Framework
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.
network
low complexity
zend CWE-77
7.5
2016-12-16 CVE-2016-6656 Command Injection vulnerability in Pivotal Software Greenplum
An issue was discovered in Pivotal Greenplum before 4.3.10.0.
network
low complexity
pivotal-software CWE-77
6.5
2016-12-14 CVE-2016-1000156 Command Injection vulnerability in Mailcwp Project Mailcwp
Mailcwp remote file upload vulnerability incomplete fix v1.100
network
low complexity
mailcwp-project CWE-77
7.5
2016-12-11 CVE-2016-6609 Command Injection vulnerability in PHPmyadmin
An issue was discovered in phpMyAdmin.
network
low complexity
phpmyadmin CWE-77
6.5
2016-12-05 CVE-2016-9835 Command Injection vulnerability in Zikula Application Framework
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
network
low complexity
zikula CWE-77
7.5
2016-11-03 CVE-2015-8969 Command Injection vulnerability in Squareup Git-Fastclone 1.0.0/1.0.1
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.
network
low complexity
square squareup CWE-77
critical
10.0
2016-11-03 CVE-2015-8968 Command Injection vulnerability in Squareup Git-Fastclone 1.0.0
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.
network
square squareup CWE-77
critical
9.3