Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-01-29 CVE-2019-10783 OS Command Injection vulnerability in Isof Project Isof
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection.
network
low complexity
isof-project CWE-78
critical
9.8
2020-01-29 CVE-2013-2573 OS Command Injection vulnerability in Tp-Link products
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G.
network
low complexity
tp-link CWE-78
critical
9.8
2020-01-29 CVE-2013-2570 OS Command Injection vulnerability in Zavio F3105 Firmware and F312A Firmware
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.
network
low complexity
zavio CWE-78
critical
9.8
2020-01-29 CVE-2013-2568 OS Command Injection vulnerability in Zavio F3105 Firmware and F312A Firmware
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
network
low complexity
zavio CWE-78
critical
9.8
2020-01-29 CVE-2019-20217 OS Command Injection vulnerability in Dlink Dir-859 Firmware 1.05/1.06B01
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled.
network
low complexity
dlink CWE-78
critical
9.8
2020-01-29 CVE-2019-20216 OS Command Injection vulnerability in Dlink Dir-859 Firmware 1.05/1.06B01
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled.
network
low complexity
dlink CWE-78
critical
9.8
2020-01-29 CVE-2019-20215 OS Command Injection vulnerability in Dlink Dir-859 Firmware 1.05/1.06B01
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled.
network
low complexity
dlink CWE-78
critical
9.8
2020-01-28 CVE-2013-1599 OS Command Injection vulnerability in Dlink products
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.
network
low complexity
dlink CWE-78
critical
9.8
2020-01-28 CVE-2012-6610 OS Command Injection vulnerability in Polycom HDX Video END Points and UC APL
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.
network
low complexity
polycom CWE-78
8.8
2020-01-28 CVE-2013-2060 OS Command Injection vulnerability in Redhat Openshift 1.0
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
network
low complexity
redhat CWE-78
critical
9.8