Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-07-25 CVE-2015-2279 OS Command Injection vulnerability in Airlive products
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac write_pid, write_msn, write_tan, or write_hdv parameter.
network
low complexity
airlive CWE-78
critical
9.8
2017-07-24 CVE-2017-11588 OS Command Injection vulnerability in Cisco Residential Gateway Firmware Ddr2200Bnaannexafccv00.00.03.45.4E/Ddr2201V1Naannexafccv00.00.03.28.3
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to the waitPingqry.cgi URI.
network
low complexity
cisco CWE-78
critical
9.8
2017-07-22 CVE-2017-2275 OS Command Injection vulnerability in Sony Wg-C10 Firmware 3.0.79
WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
network
low complexity
sony CWE-78
7.2
2017-07-18 CVE-2017-6320 OS Command Injection vulnerability in Barracuda Load Balancer ADC
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell commands and gain root privileges.
network
low complexity
barracuda CWE-78
8.8
2017-07-18 CVE-2017-1318 OS Command Injection vulnerability in IBM MQ Appliance
IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution.
network
low complexity
ibm CWE-78
8.8
2017-07-17 CVE-2017-11318 OS Command Injection vulnerability in Cobiansoft Cobian Backup 11
Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed.
network
high complexity
cobiansoft CWE-78
8.1
2017-07-17 CVE-2017-1000009 OS Command Injection vulnerability in Akeneo Product Information Management
Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.
network
low complexity
akeneo CWE-78
critical
9.8
2017-07-12 CVE-2017-4053 OS Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-78
critical
9.8
2017-07-10 CVE-2017-7175 OS Command Injection vulnerability in Nfsen 1.2.3/1.3.7
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).
network
low complexity
nfsen CWE-78
critical
9.9
2017-07-07 CVE-2017-2237 OS Command Injection vulnerability in Toshiba Hem-Gw16A Firmware and Hem-Gw26A Firmware
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier.
network
low complexity
toshiba CWE-78
critical
9.8