VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,155)

page 212 of 258
  • CVE-2023-37897HigJul 18, 2023
    risk 0.40cvss 7.2epss 0.03

    Grav is a file-based Web-platform built in PHP. Grav is subject to a server side template injection (SSTI) vulnerability. The fix for another SSTI vulnerability using `|map`, `|filter` and `|reduce` twigs implemented in the commit `71bbed1` introduces bypass of the denylist due…

  • CVE-2023-32679HigMay 19, 2023
    risk 0.40cvss 7.2epss 0.02

    Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() ->…

  • CVE-2022-47052MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    The web interface of the 'Nighthawk R6220 AC1200 Smart Wi-Fi Router' is vulnerable to a CRLF Injection attack that can be leveraged to perform Reflected XSS and HTML Injection. A malicious unauthenticated attacker can exploit this vulnerability using a specially crafted URL.…

  • CVE-2022-41878HigNov 10, 2022
    risk 0.40cvss 7.2epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywords that are specified in the Parse Server option `requestKeywordDenylist` can be injected via Cloud Code Webhooks or Triggers.…

  • CVE-2022-38796MedSep 14, 2022
    risk 0.40cvss 6.1epss 0.01

    A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.

  • CVE-2022-38191MedAug 15, 2022
    risk 0.40cvss 6.1epss 0.01

    There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.

  • CVE-2022-30991MedMay 18, 2022
    risk 0.40cvss 6.1epss 0.01

    HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2022-22344MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting,…

  • CVE-2022-21705HigFeb 23, 2022
    risk 0.40cvss 7.2epss 0.09

    Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to…

  • CVE-2021-45818MedDec 30, 2021
    risk 0.40cvss 6.1epss 0.01

    SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.

  • CVE-2021-36322MedNov 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections.

  • CVE-2021-32827MedAug 16, 2021
    risk 0.40cvss 6.1epss 0.02

    MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine.…

  • CVE-2021-37541MedAug 6, 2021
    risk 0.40cvss 6.1epss 0.01

    In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

  • CVE-2021-20101MedJun 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.

  • CVE-2021-29414MedMay 21, 2021
    risk 0.40cvss 6.1epss 0.00

    STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

  • CVE-2021-21510MedMar 8, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

  • CVE-2021-20644MedFeb 12, 2021
    risk 0.40cvss 6.1epss 0.01

    ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

  • CVE-2020-26081MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of…

  • CVE-2020-26884MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

  • CVE-2020-27627MedNov 16, 2020
    risk 0.40cvss 6.1epss 0.01

    JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.