CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,155)
page 213 of 258| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15277 | Hig | 0.40 | 7.2 | 0.02 | Oct 30, 2020 | baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1. | ||
| CVE-2020-13262 | Med | 0.40 | 6.1 | 0.01 | Jun 19, 2020 | Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link | ||
| CVE-2019-16385 | Med | 0.40 | 6.1 | 0.01 | Jun 4, 2020 | Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload.… | ||
| CVE-2020-3884 | Med | 0.40 | 6.1 | 0.01 | Apr 1, 2020 | An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution. | ||
| CVE-2020-11441 | Med | 0.40 | 6.1 | 0.02 | Mar 31, 2020 | phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable. | ||
| CVE-2019-12416 | Med | 0.40 | 6.1 | 0.03 | Mar 19, 2020 | we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default. | ||
| CVE-2015-3154 | Med | 0.40 | 6.1 | 0.01 | Jan 27, 2020 | CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email. | ||
| CVE-2019-6034 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors. | ||
| CVE-2019-15259 | Med | 0.40 | 6.1 | 0.01 | Oct 2, 2019 | A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of… | ||
| CVE-2019-16532 | Med | 0.40 | 6.1 | 0.01 | Sep 26, 2019 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. | ||
| CVE-2019-5314 | Med | 0.40 | 6.1 | 0.01 | Sep 13, 2019 | Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability. | ||
| CVE-2014-10386 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | ||
| CVE-2014-10394 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. | ||
| CVE-2014-10391 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | ||
| CVE-2019-1020006 | Med | 0.40 | 6.1 | 0.01 | Jul 29, 2019 | invenio-app before 1.1.1 allows host header injection. | ||
| CVE-2019-3562 | Med | 0.40 | 6.1 | 0.01 | Apr 29, 2019 | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11. | ||
| CVE-2015-5462 | Med | 0.40 | 6.1 | 0.01 | Apr 3, 2019 | AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features. | ||
| CVE-2018-16627 | Med | 0.40 | 6.1 | 0.01 | Dec 20, 2018 | panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature. | ||
| CVE-2018-1474 | Med | 0.40 | 6.1 | 0.01 | Dec 12, 2018 | IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to… | ||
| CVE-2018-18207 | Med | 0.40 | 6.1 | 0.01 | Oct 10, 2018 | Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter. |
- risk 0.40cvss 7.2epss 0.02
baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.
- risk 0.40cvss 6.1epss 0.01
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
- risk 0.40cvss 6.1epss 0.01
Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload.…
- risk 0.40cvss 6.1epss 0.01
An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.
- risk 0.40cvss 6.1epss 0.02
phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.
- risk 0.40cvss 6.1epss 0.03
we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.
- risk 0.40cvss 6.1epss 0.01
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
- risk 0.40cvss 6.1epss 0.01
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of…
- risk 0.40cvss 6.1epss 0.01
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
- risk 0.40cvss 6.1epss 0.01
Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.
- risk 0.40cvss 6.1epss 0.01
The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.
- risk 0.40cvss 6.1epss 0.01
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
- risk 0.40cvss 6.1epss 0.01
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
- risk 0.40cvss 6.1epss 0.01
invenio-app before 1.1.1 allows host header injection.
- risk 0.40cvss 6.1epss 0.01
A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.
- risk 0.40cvss 6.1epss 0.01
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
- risk 0.40cvss 6.1epss 0.01
panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.
- risk 0.40cvss 6.1epss 0.01
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to…
- risk 0.40cvss 6.1epss 0.01
Virtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.