CWE-88 - CERT CVE

CWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

CAPEC ID Naziv
CAPEC-137 Parameter Injection
CAPEC-174 Flash Parameter Injection
CAPEC-41 Using Meta-characters in E-mail Headers to Inject Malicious Payloads
CAPEC-460 HTTP Parameter Pollution (HPP)
CAPEC-88 OS Command Injection