Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2011-11-30 CVE-2011-4002 OS Command Injection vulnerability in Mawashimono Nikki
HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
network
low complexity
mawashimono CWE-78
7.5
2011-11-22 CVE-2011-4502 OS Command Injection vulnerability in multiple products
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.
network
low complexity
edimax canyon-tech sitecom sweex CWE-78
critical
10.0
2011-11-04 CVE-2011-1513 OS Command Injection vulnerability in E107
Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.
network
low complexity
e107 CWE-78
7.5
2011-05-20 CVE-2011-2148 OS Command Injection vulnerability in Smartertools Smarterstats 6.0
Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPassword_SettingText parameter, (3) the ctl00%24MPH%24txtSmarterLogDirectory parameter, (4) the ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEngines_SettingCheckBox%2414 parameter, (5) the ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter, or (6) the ctl00_MPH_grdLogLocations_HiddenLSR parameter, related to an "OS command injection" issue.
network
low complexity
smartertools CWE-78
critical
10.0
2011-05-05 CVE-2011-1904 OS Command Injection vulnerability in Proofpoint Messaging Security Gateway and Protection Server
An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, 5.5.5, 6.0.2, 6.1.1, and 6.2.0 allows remote attackers to execute arbitrary commands via unknown vectors, related to a "command injection" issue.
network
low complexity
proofpoint CWE-78
7.5
2011-03-11 CVE-2011-0456 OS Command Injection vulnerability in Otrs
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
network
low complexity
otrs CWE-78
7.5
2011-02-25 CVE-2011-0382 OS Command Injection vulnerability in Cisco products
The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.
network
low complexity
cisco CWE-78
critical
10.0
2011-02-25 CVE-2011-0381 OS Command Injection vulnerability in Cisco Telepresence Manager
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf97085.
network
low complexity
cisco CWE-78
critical
10.0
2011-02-25 CVE-2011-0378 OS Command Injection vulnerability in Cisco products
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
low complexity
cisco CWE-78
8.3
2011-02-25 CVE-2011-0375 OS Command Injection vulnerability in Cisco products
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCth24671.
network
low complexity
cisco CWE-78
critical
9.0