VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 18 of 274
  • CVE-2021-43350CriNov 11, 2021
    risk 0.57cvss 9.8epss 0.05

    An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized content into the LDAP filter.

  • CVE-2021-41170CriNov 8, 2021
    risk 0.57cvss 9.8epss 0.02

    neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a…

  • CVE-2021-31988HigOct 5, 2021
    risk 0.57cvss 8.8epss 0.01

    A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.

  • CVE-2020-18875HigAug 18, 2021
    risk 0.57cvss 8.8epss 0.02

    Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.

  • CVE-2021-32756HigJul 21, 2021
    risk 0.57cvss 8.8epss 0.02

    ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string which would be evaluated. Successful exploitation will…

  • CVE-2021-27903CriJun 30, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

  • CVE-2021-20574HigJun 28, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.

  • CVE-2021-24002HigJun 24, 2021
    risk 0.57cvss 8.8epss 0.01

    When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox <…

  • CVE-2021-25682HigJun 11, 2021
    risk 0.57cvss 8.8epss 0.00

    It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

  • CVE-2021-30506HigJun 4, 2021
    risk 0.57cvss 8.8epss 0.01

    Incorrect security UI in Web App Installs in Google Chrome on Android prior to 90.0.4430.212 allowed an attacker who convinced a user to install a web application to inject scripts or HTML into a privileged page via a crafted HTML page.

  • CVE-2021-26543HigMay 6, 2021
    risk 0.57cvss 8.8epss 0.02

    The "gitDiff" function in Wayfair git-parse <=1.0.4 has a command injection vulnerability. Clients of the git-parse library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. The issue has been resolved in version 1.0.5.

  • CVE-2021-0268HigApr 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device and exfiltration…

  • CVE-2021-27182HigApr 14, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email message. It allows an attacker to perform any action with the privileges of the attacked user.

  • CVE-2021-26068HigFeb 22, 2021
    risk 0.57cvss 8.8epss 0.03

    An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via a template injection vulnerability.

  • CVE-2020-12873HigFeb 19, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running…

  • CVE-2021-27185CriFeb 10, 2021
    risk 0.57cvss 9.8epss 0.05

    The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.

  • CVE-2020-16268HigDec 29, 2020
    risk 0.57cvss 8.8epss 0.01

    The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module.…

  • CVE-2020-27687HigDec 18, 2020
    risk 0.57cvss 8.8epss 0.02

    ThingsBoard before v3.2 is vulnerable to Host header injection in password-reset emails. This allows an attacker to send malicious links in password-reset emails to victims, pointing to an attacker-controlled server. Lack of validation of the Host header allows this to happen.

  • CVE-2020-25967HigDec 10, 2020
    risk 0.57cvss 8.8epss 0.01

    The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.

  • CVE-2020-12855HigAug 26, 2020
    risk 0.57cvss 8.8epss 0.02

    A Host header injection vulnerability has been discovered in SecZetta NEProfile 3.3.11. Authenticated remote adversaries can poison this header resulting in an adversary controlling the execution flow for the 302 HTTP status.