Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-09-13 CVE-2017-14405 OS Command Injection vulnerability in Eyesofnetwork 5.10
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
network
low complexity
eyesofnetwork CWE-78
7.2
2017-09-07 CVE-2017-6796 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-78
6.7
2017-09-07 CVE-2017-13713 OS Command Injection vulnerability in Twsz Wifi Repeater Firmware
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.
network
low complexity
twsz CWE-78
8.8
2017-09-04 CVE-2017-14135 OS Command Injection vulnerability in Dreambox Opendreambox 2.0
enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI.
network
low complexity
dreambox CWE-78
critical
9.8
2017-09-04 CVE-2017-14127 OS Command Injection vulnerability in Technicolor Td5336 Firmware 7.0
Command Injection in the Ping Module in the Web Interface on Technicolor TD5336 OI_Fw_v7 devices allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the pingAddr parameter to mnt_ping.cgi.
network
low complexity
technicolor CWE-78
critical
9.8
2017-09-03 CVE-2017-14119 OS Command Injection vulnerability in Eyesofnetwork 5.10
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\snmpwalk.php does not properly restrict popen calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in a parameter.
network
low complexity
eyesofnetwork CWE-78
8.8
2017-09-03 CVE-2017-14118 OS Command Injection vulnerability in Eyesofnetwork 5.10
In the EyesOfNetwork web interface (aka eonweb) 5.1-0, module\tool_all\tools\interface.php does not properly restrict exec calls, which allows remote attackers to execute arbitrary commands via shell metacharacters in the host_list parameter to module/tool_all/select_tool.php.
network
low complexity
eyesofnetwork CWE-78
8.8
2017-09-02 CVE-2017-14100 OS Command Injection vulnerability in Digium Asterisk
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible.
network
low complexity
digium CWE-78
critical
9.8
2017-08-31 CVE-2015-5958 OS Command Injection vulnerability in PHPfilemanager Project PHPfilemanager 0.9.8
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
network
low complexity
phpfilemanager-project CWE-78
8.8
2017-08-29 CVE-2017-10951 OS Command Injection vulnerability in Foxitsoftware Foxit Reader 8.3.0.14878
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878.
network
low complexity
foxitsoftware CWE-78
8.8