Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-04-25 | CVE-2018-16216 | OS Command Injection vulnerability in Audiocodes 405Hd Firmware 2.2.12 A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or opening a reverse shell) via a POST request to the web server. | 8.0 |
2019-04-24 | CVE-2018-20434 | OS Command Injection vulnerability in Librenms 1.46 LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling. | 9.8 |
2019-04-22 | CVE-2019-11444 | OS Command Injection vulnerability in Liferay Portal 7.1.2 An issue was discovered in Liferay Portal CE 7.1.2 GA3. | 7.2 |
2019-04-18 | CVE-2019-9161 | OS Command Injection vulnerability in Xinruidz Sundray WAN Controller Firmware 3.7.4.2 WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password. | 9.8 |
2019-04-18 | CVE-2019-11322 | OS Command Injection vulnerability in Motorola CX2 Firmware and M2 Firmware An issue was discovered in Motorola CX2 1.01 and M2 1.01. | 9.8 |
2019-04-18 | CVE-2019-11319 | OS Command Injection vulnerability in Motorola CX2 Firmware and M2 Firmware An issue was discovered in Motorola CX2 1.01 and M2 1.01. | 9.8 |
2019-04-18 | CVE-2019-1829 | OS Command Injection vulnerability in Cisco Aironet Access Point Firmware A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication. | 6.7 |
2019-04-18 | CVE-2019-1725 | OS Command Injection vulnerability in Cisco Unified Computing System A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk. | 5.5 |
2019-04-15 | CVE-2019-4202 | OS Command Injection vulnerability in IBM API Connect IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. | 10.0 |
2019-04-15 | CVE-2019-0232 | OS Command Injection vulnerability in Apache Tomcat When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. | 8.1 |