CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

359 vulnerabilities with CWE-88
CVE-2018-11019 HIGH
Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 - Code Injection
CVSS 7.5
CVE-2018-17456 CRITICAL
Malicious Git HTTP Server For CVE-2018-17456
CVSS 9.8
CVE-2018-3856 CRITICAL
Samsung STH-ETH-250 Firmware 0.20.17 - OS Command Injection via RTSP URL Field
CVSS 9.9
CVE-2018-13386 HIGH
Sourcetree for Windows <2.6.9 - Command Injection
CVSS 8.1
CVE-2018-13385 CRITICAL
Sourcetree for macOS <2.7.6 - Command Injection
CVSS 9.8
CVE-2018-0345 HIGH
Cisco SD-WAN Solution - Command Injection
CVSS 8.8
CVE-2018-10992 CRITICAL
LilyPond 2.19.80 - Command Injection
CVSS 9.8
CVE-2017-15694 MEDIUM
Apache Geode <1.9.0 - Privilege Escalation
CVSS 6.5
CVE-2017-14591 CRITICAL
Atlassian Fisheye/Crucible <4.4.3 & 4.5.0 - Code Injection
CVSS 9.0
CVE-2017-1001003 CRITICAL
mathjs < 3.17.0 - Prototype Pollution via Unicode Character Bypass
CVSS 9.8
CVE-2016-1000222 HIGH
Logstash < 2.1.1 - Argument Injection via CSV Output
CVSS 7.5
CVE-2016-10033 CRITICAL KEV
PHPMailer Sendmail Argument Injection
CVSS 9.8
CVE-2007-0882
Solaris 10 and 11 - Unauthenticated Argument Injection in telnetd via -f Sequence
CVE-2006-6597
HyperAccess 8.4 - Command Injection
CVE-2006-4692
Microsoft Windows XP <SP2 - Command Injection
CVE-2006-3015
WinSCP 3.8.1 - Argument Injection via Encoded Spaces in SCP/SFTP URI
CVE-2006-2312
Skype < 2.0.0.105 - Argument Injection via URI Handler
CVE-2006-2055
Microsoft Outlook 2003 SP1 - Command Injection
CVE-2006-2056
Internet Explorer 6 for Windows XP SP2 - Command Injection
CVE-2006-2057
Mozilla Firefox 1.0.6 - Command Injection
CVE-2006-2058
Avant Browser 10.1 Build 17 - Command Injection
CVE-2006-1865
Beagle < 0.2.5 - OS Command Injection via Crafted Filename Argument Injection
CVE-2005-4699
kimihia tellme < 1.2 - Argument Injection via q_Host Parameter
CVE-2004-0480
IBM Lotus Notes <6.5 - Command Injection
CVE-2004-0411
Konqueror < 3.2.2 - Command Injection via URI Handler Hostname
Details
Vulnerabilities 359