CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 20 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-7381 | Cri | 0.57 | 9.8 | 0.03 | Feb 12, 2020 | libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify. | ||
| CVE-2013-7378 | Cri | 0.57 | 9.8 | 0.03 | Feb 12, 2020 | scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands. | ||
| CVE-2013-2678 | Hig | 0.57 | 8.1 | 0.17 | Feb 4, 2020 | Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter. | ||
| CVE-2020-7596 | Hig | 0.57 | 8.8 | 0.02 | Jan 25, 2020 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | ||
| CVE-2014-4172 | Cri | 0.57 | 9.8 | 0.06 | Jan 24, 2020 | A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via… | ||
| CVE-2013-7070 | Cri | 0.57 | 9.8 | 0.04 | Dec 31, 2019 | The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI. | ||
| CVE-2019-19919 | Cri | 0.57 | 9.8 | 0.07 | Dec 20, 2019 | Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads. | ||
| CVE-2019-8792 | Hig | 0.57 | 8.8 | 0.02 | Dec 18, 2019 | An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution. | ||
| CVE-2013-4486 | Cri | 0.57 | 9.8 | 0.01 | Dec 3, 2019 | Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging | ||
| CVE-2019-8135 | Cri | 0.57 | 9.8 | 0.02 | Nov 6, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution. | ||
| CVE-2019-12463 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with… | ||
| CVE-2019-5404 | Hig | 0.57 | 8.8 | 0.02 | Aug 9, 2019 | A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1. | ||
| CVE-2016-10801 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 has improper session handling for shared users (SEC-139). | ||
| CVE-2019-12303 | Hig | 0.57 | 8.8 | 0.02 | Jun 6, 2019 | In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container. | ||
| CVE-2016-8900 | Cri | 0.57 | 9.8 | 0.02 | May 24, 2019 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags. | ||
| CVE-2016-8899 | Cri | 0.57 | 9.8 | 0.02 | May 23, 2019 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats. | ||
| CVE-2016-8901 | Cri | 0.57 | 9.8 | 0.03 | May 23, 2019 | b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. | ||
| CVE-2019-9614 | Hig | 0.57 | 8.8 | 0.03 | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command. | ||
| CVE-2018-18992 | Hig | 0.57 | 8.8 | 0.02 | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server. | ||
| CVE-2018-16492 | Cri | 0.57 | 9.8 | 0.03 | Feb 1, 2019 | A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype. |
- risk 0.57cvss 9.8epss 0.03
libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.
- risk 0.57cvss 9.8epss 0.03
scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.
- risk 0.57cvss 8.1epss 0.17
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
- risk 0.57cvss 8.8epss 0.02
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
- risk 0.57cvss 9.8epss 0.06
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via…
- risk 0.57cvss 9.8epss 0.04
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
- risk 0.57cvss 9.8epss 0.07
Versions of handlebars prior to 4.3.0 are vulnerable to Prototype Pollution leading to Remote Code Execution. Templates may alter an Object's __proto__ and __defineGetter__ properties, which may allow an attacker to execute arbitrary code through crafted payloads.
- risk 0.57cvss 8.8epss 0.02
An injection issue was addressed with improved validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.
- risk 0.57cvss 9.8epss 0.01
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
- risk 0.57cvss 9.8epss 0.02
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dependency injection through Symphony framework allows service identifiers to be derived from user controlled data, which can lead to remote code execution.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with…
- risk 0.57cvss 8.8epss 0.02
A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
- risk 0.57cvss 8.8epss 0.02
In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrary commands inside the fluentd container.
- risk 0.57cvss 9.8epss 0.02
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
- risk 0.57cvss 9.8epss 0.02
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
- risk 0.57cvss 9.8epss 0.03
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
- risk 0.57cvss 8.8epss 0.03
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.
- risk 0.57cvss 8.8epss 0.02
LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server.
- risk 0.57cvss 9.8epss 0.03
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.