Vulnerabilities (CVE)

Filtered by CWE-78
Total 3837 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7640 1 Qnap 2 Media Streaming Add-on, Qts 2018-03-27 10.0 HIGH 9.8 CRITICAL
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
CVE-2018-7664 1 Clip-bucket 1 Clipbucket 2018-03-27 10.0 HIGH 9.8 CRITICAL
An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php.
CVE-2018-0523 1 Buffalo 2 Wxr-1900dhp2, Wxr-1900dhp2 Firmware 2018-03-26 8.3 HIGH 8.8 HIGH
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
CVE-2015-4117 1 Vestacp 1 Control Panel 2018-03-23 6.5 MEDIUM 8.8 HIGH
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.
CVE-2018-7448 1 Cmsmadesimple 1 Cms Made Simple 2018-03-22 8.5 HIGH 7.5 HIGH
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
CVE-2016-0291 1 Ibm 1 Bigfix Platform 2018-03-17 9.0 HIGH 8.8 HIGH
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302.
CVE-2017-6230 1 Ruckuswireless 2 Smartzone Managed Access Point Firmware, Solo Access Point Firmware 2018-03-16 9.0 HIGH 8.8 HIGH
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
CVE-2018-6926 1 Misp 1 Misp 2018-03-16 9.0 HIGH 7.2 HIGH
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.
CVE-2017-6229 1 Ruckuswireless 30 H320, H320 Firmware, H510 and 27 more 2018-03-12 9.0 HIGH 8.8 HIGH
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 10.1.0.0.x, 9.10.2.0.x, 9.12.3.0.x, 9.13.3.0.x, 10.0.1.0.x or before contain authenticated Root Command Injection in the CLI that could allow authenticated valid users to execute privileged commands on the respective systems.
CVE-2018-0514 1 Futomi 1 Mp Form Mail Cgi 2018-03-10 10.0 HIGH 9.8 CRITICAL
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2018-0512 1 Iodata 90 Bx-vp1, Bx-vp1 Firmware, Gv-ntx1 and 87 more 2018-03-06 7.7 HIGH 6.8 MEDIUM
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2018-1000043 1 Securityonion 1 Squert 2018-03-01 10.0 HIGH 9.8 CRITICAL
Security Onion Solutions Squert version 1.0.1 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payload in the txdata parameter, used in tx()/transcript(), or the catdata parameter, used in cat(). This vulnerability appears to have been fixed in 1.7.0.
CVE-2018-1000042 1 Securityonion 1 Squert 2018-03-01 10.0 HIGH 9.8 CRITICAL
Security Onion Solutions Squert version 1.3.0 through 1.6.7 contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in .inc/callback.php that can result in execution of OS Commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payload in the data or obj parameters, used in autocat(). This vulnerability appears to have been fixed in 1.7.0.
CVE-2018-1000019 1 Open-emr 1 Openemr 2018-03-01 9.0 HIGH 8.8 HIGH
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
CVE-2018-6353 1 Electrum 1 Electrum 2018-02-15 7.2 HIGH 7.8 HIGH
The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for attackers to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.
CVE-2018-6388 1 Iball 2 Ib-wra150n, Ib-wra150n Firmware 2018-02-15 9.0 HIGH 8.8 HIGH
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.
CVE-2018-0506 1 Nootka Project 1 Nootka 2018-02-13 10.0 HIGH 9.8 CRITICAL
Nootka 1.4.4 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2017-1000502 1 Jenkins 1 Ec2 2018-02-12 9.0 HIGH 8.8 HIGH
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the 'Run Scripts' permission typically only granted to administrators.
CVE-2016-10709 1 Pfsense 1 Pfsense 2018-02-09 9.0 HIGH 8.8 HIGH
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.
CVE-2017-1000473 1 Linux-dash Project 1 Linux-dash 2018-01-19 7.2 HIGH 7.8 HIGH
Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root.