VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 226 of 274
  • CVE-2022-22344MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting,…

  • CVE-2022-21705HigFeb 23, 2022
    risk 0.40cvss 7.2epss 0.09

    Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to…

  • CVE-2021-45818MedDec 30, 2021
    risk 0.40cvss 6.1epss 0.01

    SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.

  • CVE-2021-36322MedNov 20, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections.

  • CVE-2021-32827MedAug 16, 2021
    risk 0.40cvss 6.1epss 0.02

    MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine.…

  • CVE-2021-37541MedAug 6, 2021
    risk 0.40cvss 6.1epss 0.01

    In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

  • CVE-2021-20101MedJun 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This could cause a victim to receive malformed content.

  • CVE-2021-29414MedMay 21, 2021
    risk 0.40cvss 6.1epss 0.00

    STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

  • CVE-2021-21510MedMar 8, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary ‘Host’ header values to poison a web-cache or trigger redirections.

  • CVE-2021-20644MedFeb 12, 2021
    risk 0.40cvss 6.1epss 0.01

    ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

  • CVE-2020-26081MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of…

  • CVE-2020-26884MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

  • CVE-2020-27627MedNov 16, 2020
    risk 0.40cvss 6.1epss 0.01

    JetBrains TeamCity before 2020.1.2 was vulnerable to URL injection.

  • CVE-2020-15277HigOct 30, 2020
    risk 0.40cvss 7.2epss 0.02

    baserCMS before version 4.4.1 is affected by Remote Code Execution (RCE). Code may be executed by logging in as a system administrator and uploading an executable script file such as a PHP file. The Edit template component is vulnerable. The issue is fixed in version 4.4.1.

  • CVE-2020-13262MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

  • CVE-2019-16385MedJun 4, 2020
    risk 0.40cvss 6.1epss 0.01

    Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer request, as demonstrated by an example.pdf?mimetype= substring. The victim user must load an application request to view a PDF, containing the malicious payload.…

  • CVE-2020-3884MedApr 1, 2020
    risk 0.40cvss 6.1epss 0.01

    An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

  • CVE-2020-11441MedMar 31, 2020
    risk 0.40cvss 6.1epss 0.02

    phpMyAdmin 5.0.2 allows CRLF injection, as demonstrated by %0D%0Astring%0D%0A inputs to login form fields causing CRLF sequences to be reflected on an error page. NOTE: the vendor states "I don't see anything specifically exploitable.

  • CVE-2019-12416MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.03

    we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selected the ClientSideWindowStrategy which is not the default.

  • CVE-2015-3154MedJan 27, 2020
    risk 0.40cvss 6.1epss 0.01

    CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.