VYPR

CWE-707

Improper Neutralization

PillarIncomplete

Description

The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-250 · CAPEC-276 · CAPEC-277 · CAPEC-278 · CAPEC-279 · CAPEC-3 · CAPEC-43 · CAPEC-468 · CAPEC-52 · CAPEC-53 · CAPEC-64 · CAPEC-7 · CAPEC-78 · CAPEC-79 · CAPEC-83 · CAPEC-84

CVEs mapped to this weakness (253)

page 13 of 13
  • CVE-2022-4513LowDec 15, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This issue affects some unknown processing. The manipulation of the argument searchTag/resourceUri leads to cross site scripting. The attack may be initiated…

  • CVE-2022-4456LowDec 13, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 15adb8e1ea1f1c3e3d152fc266071f621ef0c621. It is…

  • CVE-2022-4454MedDec 13, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handler. The manipulation leads to sql injection. The name of…

  • CVE-2022-4444LowDec 13, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.13.0 is able to address this…

  • CVE-2022-4421LowDec 12, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of the file themes/default/servicedesk/view.php of the component Service Desk Image URL Handler. The manipulation of the argument sslink leads to cross site…

  • CVE-2022-4399MedDec 10, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/db.c. The manipulation of the argument value/name leads to sql injection. The name of the patch is…

  • CVE-2022-3988LowNov 14, 2022
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functionality of the file frappe/templates/includes/navbar/navbar_search.html of the component Search. The manipulation of the argument q leads to cross site scripting.…

  • CVE-2022-3968LowNov 13, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/article_save.php. The manipulation of the argument tag leads to cross site scripting. The attack can be launched remotely. The name…

  • CVE-2022-3967MedNov 13, 2022
    risk 0.00cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of the file func/main.sh of the component sed Handler. The manipulation leads to argument injection. An attack has to be approached locally. The name of the patch…

  • CVE-2022-3963LowNov 12, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to cross site scripting. It is possible to launch the attack…

  • CVE-2022-3950LowNov 11, 2022
    risk 0.00cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of…

  • CVE-2022-3845LowNov 2, 2022
    risk 0.00cvss 2.4epss 0.01

    A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/admin/import-export/import-load-data.php of the component Import Preview Handler. The manipulation leads to cross site scripting.…

  • CVE-2020-11080LowJun 3, 2020
    risk 0.00cvss 3.7epss 0.05

    In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again.…