Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-04-25 CVE-2018-16216 OS Command Injection vulnerability in Audiocodes 405Hd Firmware 2.2.12
A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or opening a reverse shell) via a POST request to the web server.
low complexity
audiocodes CWE-78
8.0
2019-04-24 CVE-2018-20434 OS Command Injection vulnerability in Librenms 1.46
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.
network
low complexity
librenms CWE-78
critical
9.8
2019-04-22 CVE-2019-11444 OS Command Injection vulnerability in Liferay Portal 7.1.2
An issue was discovered in Liferay Portal CE 7.1.2 GA3.
network
low complexity
liferay CWE-78
7.2
2019-04-18 CVE-2019-9161 OS Command Injection vulnerability in Xinruidz Sundray WAN Controller Firmware 3.7.4.2
WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote attackers to achieve full access to the system, because shell metacharacters in the nginx_webconsole.php Cookie header can be used to read an etc/config/wac/wns_cfg_admin_detail.xml file containing the admin password.
network
low complexity
xinruidz CWE-78
critical
9.8
2019-04-18 CVE-2019-11322 OS Command Injection vulnerability in Motorola CX2 Firmware and M2 Firmware
An issue was discovered in Motorola CX2 1.01 and M2 1.01.
network
low complexity
motorola CWE-78
critical
9.8
2019-04-18 CVE-2019-11319 OS Command Injection vulnerability in Motorola CX2 Firmware and M2 Firmware
An issue was discovered in Motorola CX2 1.01 and M2 1.01.
network
low complexity
motorola CWE-78
critical
9.8
2019-04-18 CVE-2019-1829 OS Command Injection vulnerability in Cisco Aironet Access Point Firmware
A vulnerability in the CLI of Cisco Aironet Series Access Points (APs) could allow an authenticated, local attacker to gain access to the underlying Linux operating system (OS) without the proper authentication.
local
low complexity
cisco CWE-78
6.7
2019-04-18 CVE-2019-1725 OS Command Injection vulnerability in Cisco Unified Computing System
A vulnerability in the local management CLI implementation for specific commands on the Cisco UCS B-Series Blade Servers could allow an authenticated, local attacker to overwrite an arbitrary file on disk.
local
low complexity
cisco CWE-78
5.5
2019-04-15 CVE-2019-4202 OS Command Injection vulnerability in IBM API Connect
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection.
network
low complexity
ibm CWE-78
critical
10.0
2019-04-15 CVE-2019-0232 OS Command Injection vulnerability in Apache Tomcat
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows.
network
high complexity
apache CWE-78
8.1