Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-03-08 CVE-2018-0224 OS Command Injection vulnerability in Cisco Staros 21.3.0.67664/21.5.0
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system.
local
low complexity
cisco CWE-78
6.7
2018-03-08 CVE-2018-0221 OS Command Injection vulnerability in Cisco Identity Services Engine
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session.
local
low complexity
cisco CWE-78
6.7
2018-03-08 CVE-2018-0217 OS Command Injection vulnerability in Cisco products
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system.
local
low complexity
cisco CWE-78
6.7
2018-03-08 CVE-2018-0214 OS Command Injection vulnerability in Cisco Identity Services Engine 2.1(102.103)
A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local user, aka Command Injection.
local
low complexity
cisco CWE-78
5.3
2018-03-07 CVE-2018-1000118 OS Command Injection vulnerability in Electronjs Electron
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute.
network
low complexity
electronjs CWE-78
8.8
2018-03-06 CVE-2018-6530 OS Command Injection vulnerability in Dlink products
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.
network
low complexity
dlink CWE-78
critical
9.8
2018-03-05 CVE-2018-7664 OS Command Injection vulnerability in Clip-Bucket Clipbucket
An issue was discovered in ClipBucket before 4.0.0 Release 4902.
network
low complexity
clip-bucket CWE-78
critical
9.8
2018-03-01 CVE-2017-9274 OS Command Injection vulnerability in Opensuse Obs-Service-Source Validator
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
local
low complexity
opensuse CWE-78
7.8
2018-02-28 CVE-2015-4117 OS Command Injection vulnerability in Vestacp Control Panel
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
network
low complexity
vestacp CWE-78
8.8
2018-02-28 CVE-2016-0291 OS Command Injection vulnerability in IBM Bigfix Platform
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access.
network
low complexity
ibm CWE-78
8.8