Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-06-19 CVE-2018-16593 OS Command Injection vulnerability in Sony products
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
low complexity
sony CWE-78
8.8
2019-06-19 CVE-2018-16618 OS Command Injection vulnerability in Vtech Storio MAX Firmware
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name.
network
low complexity
vtech CWE-78
critical
9.8
2019-06-19 CVE-2018-18472 OS Command Injection vulnerability in Westerndigital MY Book Live Firmware
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.
network
low complexity
westerndigital CWE-78
critical
9.8
2019-06-18 CVE-2018-18852 OS Command Injection vulnerability in Cerio Dt-300N Firmware 1.1.12/1.1.6
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
network
low complexity
cerio CWE-78
8.8
2019-06-17 CVE-2019-11410 OS Command Injection vulnerability in Fusionpbx 4.4.3
app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation, which allows authenticated administrative attackers to execute commands on the host.
network
low complexity
fusionpbx CWE-78
7.2
2019-06-17 CVE-2019-11409 OS Command Injection vulnerability in Fusionpbx 4.4.3
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lack of input validation that allows authenticated non-administrative attackers to execute commands on the host.
network
low complexity
fusionpbx CWE-78
8.8
2019-06-17 CVE-2019-12181 OS Command Injection vulnerability in Solarwinds Serv-U FTP Server and Serv-U MFT Server
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
network
low complexity
solarwinds CWE-78
8.8
2019-06-15 CVE-2019-12840 OS Command Injection vulnerability in Webmin
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
network
low complexity
webmin CWE-78
8.8
2019-06-15 CVE-2019-12839 OS Command Injection vulnerability in Orangehrm
In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath parameter) that allows authenticated attackers to achieve arbitrary command execution.
network
low complexity
orangehrm CWE-78
8.8
2019-06-11 CVE-2018-20841 OS Command Injection vulnerability in Hootoo Tripmate Titan Ht-Tm05 Firmware 2.000.022/2.000.082
HooToo TripMate Titan HT-TM05 and HT-05 routers with firmware 2.000.022 and 2.000.082 allow remote command execution via shell metacharacters in the mac parameter of a protocol.csp?function=set&fname=security&opt=mac_table request.
network
low complexity
hootoo CWE-78
critical
9.8