CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 32 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29702 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2021 | Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658. | ||
| CVE-2021-33668 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2021 | Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application. | ||
| CVE-2021-3154 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2021 | An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481. | ||
| CVE-2021-31164 | Hig | 0.49 | 7.5 | 0.02 | May 4, 2021 | Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. | ||
| CVE-2021-22331 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2021 | There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service.… | ||
| CVE-2021-21420 | Hig | 0.49 | 7.5 | 0.01 | Apr 1, 2021 | vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary… | ||
| CVE-2020-35564 | Hig | 0.49 | 7.5 | 0.01 | Feb 16, 2021 | An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code. | ||
| CVE-2021-23335 | Hig | 0.49 | 7.5 | 0.01 | Feb 11, 2021 | All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure. | ||
| CVE-2021-21278 | Hig | 0.49 | 8.6 | 0.02 | Jan 26, 2021 | RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code,… | ||
| CVE-2020-29655 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2020 | An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker… | ||
| CVE-2017-18923 | Hig | 0.49 | 7.5 | 0.01 | Jul 29, 2020 | beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials. | ||
| CVE-2020-11994 | Hig | 0.49 | 7.5 | 0.04 | Jul 8, 2020 | Server-Side Template Injection and arbitrary file disclosure on Camel templating components | ||
| CVE-2019-13285 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2020 | CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection. | ||
| CVE-2019-12425 | Hig | 0.49 | 7.5 | 0.05 | Apr 30, 2020 | Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host | ||
| CVE-2020-11709 | Hig | 0.49 | 7.5 | 0.02 | Apr 12, 2020 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts. | ||
| CVE-2020-11703 | Hig | 0.49 | 7.5 | 0.01 | Apr 12, 2020 | An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter. | ||
| CVE-2020-11593 | Hig | 0.49 | 7.5 | 0.01 | Apr 6, 2020 | An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address. | ||
| CVE-2019-19614 | Hig | 0.49 | 7.5 | 0.01 | Mar 9, 2020 | An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1. | ||
| CVE-2019-16468 | Hig | 0.49 | 7.5 | 0.03 | Jan 15, 2020 | Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure. | ||
| CVE-2012-0070 | Hig | 0.49 | 7.5 | 0.01 | Jan 15, 2020 | spamdyke prior to 4.2.1: STARTTLS reveals plaintext |
- risk 0.49cvss 7.5epss 0.02
Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.
- risk 0.49cvss 7.5epss 0.01
Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.
- risk 0.49cvss 7.5epss 0.02
Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
- risk 0.49cvss 7.5epss 0.01
There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service.…
- risk 0.49cvss 7.5epss 0.01
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary…
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
- risk 0.49cvss 7.5epss 0.01
All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.
- risk 0.49cvss 8.6epss 0.02
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code,…
- risk 0.49cvss 7.5epss 0.01
An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker…
- risk 0.49cvss 7.5epss 0.01
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
- risk 0.49cvss 7.5epss 0.04
Server-Side Template Injection and arbitrary file disclosure on Camel templating components
- risk 0.49cvss 7.5epss 0.01
CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
- risk 0.49cvss 7.5epss 0.05
Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
- risk 0.49cvss 7.5epss 0.02
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1.
- risk 0.49cvss 7.5epss 0.03
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
- risk 0.49cvss 7.5epss 0.01
spamdyke prior to 4.2.1: STARTTLS reveals plaintext