CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

394 vulnerabilities with CWE-88
CVE-2021-3256 MEDIUM
KuaiFanCMS V5.x - Arbitrary File Read via chakanhtml.module.php html_url Parameter
CVSS 6.5
CVE-2021-33564 CRITICAL
Dragonfly <1.4.0 - Command Injection
CVSS 9.8
CVE-2021-1531 HIGH
Cisco Modeling Labs - Command Injection
CVSS 8.8
CVE-2021-31909 CRITICAL
JetBrains TeamCity < 2020.2.3 - Remote Code Execution via Argument Injection
CVSS 9.8
CVE-2021-29472 HIGH
Composer < 1.10.22 - Remote Code Execution via Mercurial Repository URL
CVSS 8.8
CVE-2021-29461 HIGH
discord-recon < 0.0.3 - Remote Code Execution via Argument Injection
CVSS 8.1
CVE-2021-1485 MEDIUM
Cisco IOS XR < 7.3.1 - Authenticated Command Injection via CLI
CVSS 6.6
CVE-2021-21386 CRITICAL
APKLeaks < 2.0.3 - OS Command Injection via Package Name in Application Manifest
CVSS 9.3
CVE-2021-1454 MEDIUM
Cisco IOS XE SD-WAN - Privilege Escalation
CVSS 6.0
CVE-2021-1383 MEDIUM
Cisco IOS XE SD-WAN - Privilege Escalation
CVSS 6.0
CVE-2021-21384 MEDIUM
shescape < 1.1.3 - Command Injection via Newline Character
CVSS 6.3
CVE-2021-24030 CRITICAL
Facebook Gameroom <1.26.0 - Code Injection
CVSS 9.8
CVE-2021-26937 CRITICAL
GNU Screen < 4.8.0 - Denial of Service via Crafted UTF-8 Character Sequence
CVSS 9.8
CVE-2021-3401 CRITICAL
Bitcoin Core < 0.19.0 - Remote Code Execution via -platformpluginpath Argument Injection
CVSS 9.8
CVE-2020-7851 HIGH
Innorix Web-Based File Transfer Solution <9.2.18.385 - RCE
CVSS 7.8
CVE-2020-7850 HIGH
Douzone NBBDownloader.ocx - Remote File Download and Execution via ActiveX Method
CVSS 7.8
CVE-2020-21224 CRITICAL
Inspur ClusterEngine V4.0 - Remote Code Execution via Malicious Login Packet
CVSS 9.8
CVE-2020-35136 HIGH
Dolibarr <12.0.3 - Authenticated RCE
CVSS 7.2
CVE-2020-7769 HIGH
nodemailer <6.4.16 - Command Injection
CVSS 8.6
CVE-2020-25268 HIGH
ILIAS 6.4 - Remote Code Execution via External News Feed Parameter
CVSS 8.8
CVE-2020-27129 MEDIUM
Cisco SD-WAN vManage Software - Command Injection
CVSS 6.7
CVE-2020-5648 CRITICAL
GOT 1000 series - Argument Injection
CVSS 9.8
CVE-2020-5657 MEDIUM
MELSEC iQ-R Series Firmware - Unauthenticated Denial of Service via Crafted TCP/IP Packet
CVSS 6.5
CVE-2020-15238 HIGH
Blueman < 2.1.4 - Command Injection via DhcpClient D-Bus Method
CVSS 7.1
CVE-2020-5792 HIGH
Nagios XI 5.7.3 - Command Injection
CVSS 7.2
Details
Vulnerabilities 394