VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 32 of 274
  • CVE-2021-29702HigJun 16, 2021
    risk 0.49cvss 7.5epss 0.02

    Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1.4 and 11.5.5 is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200658.

  • CVE-2021-33668HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.

  • CVE-2021-3154HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

  • CVE-2021-31164HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.02

    Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.

  • CVE-2021-22331HigApr 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service.…

  • CVE-2021-21420HigApr 1, 2021
    risk 0.49cvss 7.5epss 0.01

    vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary…

  • CVE-2020-35564HigFeb 16, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.

  • CVE-2021-23335HigFeb 11, 2021
    risk 0.49cvss 7.5epss 0.01

    All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.

  • CVE-2021-21278HigJan 26, 2021
    risk 0.49cvss 8.6epss 0.02

    RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code,…

  • CVE-2020-29655HigDec 9, 2020
    risk 0.49cvss 7.5epss 0.01

    An injection vulnerability exists in RT-AC88U Download Master before 3.1.0.108. Accessing Main_Login.asp?flag=1&productname=FOOBAR&url=/downloadmaster/task.asp will redirect to the login site, which will show the value of the parameter productname within the title. An attacker…

  • CVE-2017-18923HigJul 29, 2020
    risk 0.49cvss 7.5epss 0.01

    beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.

  • CVE-2020-11994HigJul 8, 2020
    risk 0.49cvss 7.5epss 0.04

    Server-Side Template Injection and arbitrary file disclosure on Camel templating components

  • CVE-2019-13285HigMay 4, 2020
    risk 0.49cvss 7.5epss 0.01

    CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.

  • CVE-2019-12425HigApr 30, 2020
    risk 0.49cvss 7.5epss 0.05

    Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host

  • CVE-2020-11709HigApr 12, 2020
    risk 0.49cvss 7.5epss 0.02

    cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.

  • CVE-2020-11703HigApr 12, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.

  • CVE-2020-11593HigApr 6, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request with injected HTML data that is later leveraged to send emails from a customer trusted email address.

  • CVE-2019-19614HigMar 9, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing an attacker to enumerate the list of users sharing an identical password. Fixed in Release 10.24.11206.1.

  • CVE-2019-16468HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2012-0070HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    spamdyke prior to 4.2.1: STARTTLS reveals plaintext