Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-11-27 CVE-2017-1000214 OS Command Injection vulnerability in Gitphp Project Gitphp
GitPHP by xiphux is vulnerable to OS Command Injections
network
low complexity
gitphp-project CWE-78
critical
9.8
2017-11-27 CVE-2017-16960 OS Command Injection vulnerability in Tp-Link products
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
network
low complexity
tp-link CWE-78
8.8
2017-11-27 CVE-2017-16958 OS Command Injection vulnerability in Tp-Link products
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
network
low complexity
tp-link CWE-78
8.8
2017-11-27 CVE-2017-16957 OS Command Injection vulnerability in Tp-Link products
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.
network
low complexity
tp-link CWE-78
8.8
2017-11-24 CVE-2017-16934 OS Command Injection vulnerability in Dbltek web Server
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.
network
low complexity
dbltek CWE-78
critical
9.8
2017-11-22 CVE-2017-16926 OS Command Injection vulnerability in Ohcount Project Ohcount 3.0.0
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) to execute arbitrary code as the user running Ohcount.
network
low complexity
ohcount-project CWE-78
critical
9.8
2017-11-21 CVE-2017-16923 OS Command Injection vulnerability in Tenda Ac15 Firmware, Ac18 Firmware and AC9 Firmware
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V15.03.05.05_multi_TD01, and Ac18 ac18_kf_V15.03.05.19(6318_)_cn devices allows remote unauthenticated attackers to execute arbitrary OS commands via a crafted cgi-bin/luci/usbeject?dev_name= GET request from the LAN.
low complexity
tenda CWE-78
8.8
2017-11-17 CVE-2017-1000215 OS Command Injection vulnerability in Xrootd 4.6.0
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
network
low complexity
xrootd CWE-78
critical
9.8
2017-11-17 CVE-2017-1000203 OS Command Injection vulnerability in Cern Root
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution
network
low complexity
cern CWE-78
8.8
2017-11-17 CVE-2017-1000235 OS Command Injection vulnerability in I-Librarian I Librarian
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
network
low complexity
i-librarian CWE-78
critical
9.8