CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

394 vulnerabilities with CWE-88
CVE-2022-37027 HIGH
Ahsay Cloud Backup Suite 9.1.4.0 - Authenticated Argument Injection via Runtime Options
CVSS 7.2
CVE-2022-36069 HIGH
Poetry < 1.1.9 - Command Injection via Git Dependency URL Argument
CVSS 7.3
CVE-2022-36804 HIGH KEV
Atlassian Bitbucket Server/Data Center <7.6.17/<7.17.10/<7.21.4/<8....
CVSS 8.8
CVE-2022-1399 CRITICAL
Device42 CMDB <18.01.00 - Command Injection
CVSS 9.1
CVE-2022-37005 HIGH
Huawei EMUI - Argument Injection in Settings Application
CVSS 7.5
CVE-2022-25973 HIGH
mc-kill-port - Arbitrary Command Execution via Port Argument Injection
CVSS 7.8
CVE-2022-36322 MEDIUM
JetBrains TeamCity <2022.04.2 - Code Injection
CVSS 5.4
CVE-2022-25900 HIGH
git-clone - Command Injection via --upload-pack Feature
CVSS 8.1
CVE-2022-31084 HIGH
LDAP Account Manager <8.0 - Code Injection
CVSS 8.1
CVE-2022-31246 MEDIUM
Electrum < 4.2.2 - Argument Injection via Payment Request URL Parameter
CVSS 5.5
CVE-2022-24376 HIGH
git-promise - Command Injection via Inappropriate Fix
CVSS 7.2
CVE-2022-26532 HIGH
Zyxel USG/ZyWALL series <4.71 - Command Injection
CVSS 7.8
CVE-2022-29215 HIGH
RegionProtect <1.1.0 - Code Injection
CVSS 7.5
CVE-2022-29184 HIGH
GoCD < 22.1.0 - Authenticated Remote Code Execution via Mercurial Hook Branch Name Injection
CVSS 8.8
CVE-2022-25865 HIGH
workspace-tools < 0.18.4 - Command Injection via Git Argument Injection
CVSS 8.1
CVE-2022-30240 HIGH
Magnitude Simba Amazon Redshift JDBC Driver <1.2.55 - Command Injec...
CVSS 7.8
CVE-2022-30239 HIGH
Magnitude Simba Amazon Athena JDBC Driver <2.0.29 - Command Injection
CVSS 7.8
CVE-2022-29972 HIGH
Magnitude Simba Amazon Redshift ODBC Driver <1.4.52 - Command Injec...
CVSS 7.8
CVE-2022-29971 HIGH
Magnitude Simba Amazon Athena ODBC Driver <1.1.17 - Command Injection
CVSS 7.8
CVE-2022-30284 CRITICAL
python-libnmap < 0.7.2 - Remote Code Execution via NmapProcess Argument Injection
CVSS 9.0
CVE-2022-24437 CRITICAL
git-pull-or-clone <2.0.2 - Command Injection
CVSS 9.8
CVE-2022-25866 HIGH
czproject/git-php < 4.0.3 - Command Injection via git ls-remote Argument Injection
CVSS 8.1
CVE-2022-25648 HIGH
git < 1.11.0 - Command Injection via fetch Remote Parameter
CVSS 8.1
CVE-2022-24828 HIGH
Composer < 1.10.26 - Command Injection via VcsDriver getFileContent
CVSS 8.3
CVE-2022-28391 HIGH
BusyBox < 1.35.0 - Remote Code Execution via netstat DNS PTR Record Handling
CVSS 8.8
Details
Vulnerabilities 394