CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 7 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34079 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file. | ||
| CVE-2020-28246 | Cri | 0.64 | 9.8 | 0.02 | Jun 2, 2022 | A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this… | ||
| CVE-2022-25420 | Cri | 0.64 | 9.8 | 0.03 | Mar 29, 2022 | NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request. | ||
| CVE-2022-26205 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2022 | Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload. | ||
| CVE-2022-25337 | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2022 | Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames. | ||
| CVE-2021-44530 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2022 | An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application. | ||
| CVE-2021-43185 | Cri | 0.64 | 9.8 | 0.02 | Nov 9, 2021 | JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection. | ||
| CVE-2021-38458 | Cri | 0.64 | 9.8 | 0.02 | Oct 12, 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. | ||
| CVE-2021-41862 | Cri | 0.64 | 9.8 | 0.02 | Oct 2, 2021 | AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL). | ||
| CVE-2021-41392 | Cri | 0.64 | 9.8 | 0.03 | Sep 17, 2021 | static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API. | ||
| CVE-2021-20509 | Cri | 0.64 | 9.8 | 0.02 | Aug 12, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243. | ||
| CVE-2020-17952 | Cri | 0.64 | 9.8 | 0.02 | Jul 26, 2021 | A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code. | ||
| CVE-2021-3169 | Cri | 0.64 | 9.8 | 0.03 | Jul 23, 2021 | An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets. | ||
| CVE-2021-27730 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2021 | Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later. | ||
| CVE-2020-7786 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2021 | This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js. | ||
| CVE-2020-7782 | Cri | 0.64 | 9.8 | 0.02 | Feb 8, 2021 | This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package. | ||
| CVE-2020-15690 | Cri | 0.64 | 9.8 | 0.03 | Jan 30, 2021 | In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character. | ||
| CVE-2020-21523 | Cri | 0.64 | 9.8 | 0.03 | Sep 30, 2020 | A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign… | ||
| CVE-2020-14505 | Cri | 0.64 | 9.8 | 0.07 | Jul 15, 2020 | Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command… | ||
| CVE-2020-8186 | Cri | 0.64 | 9.8 | 0.03 | Jul 10, 2020 | A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function. |
- risk 0.64cvss 9.8epss 0.04
OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.
- risk 0.64cvss 9.8epss 0.02
A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this…
- risk 0.64cvss 9.8epss 0.03
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.02
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.
- risk 0.64cvss 9.8epss 0.01
Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.
- risk 0.64cvss 9.8epss 0.01
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
- risk 0.64cvss 9.8epss 0.02
JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
- risk 0.64cvss 9.8epss 0.02
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- risk 0.64cvss 9.8epss 0.02
AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).
- risk 0.64cvss 9.8epss 0.03
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
- risk 0.64cvss 9.8epss 0.02
IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.
- risk 0.64cvss 9.8epss 0.02
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.
- risk 0.64cvss 9.8epss 0.03
An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
- risk 0.64cvss 9.8epss 0.01
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
- risk 0.64cvss 9.8epss 0.02
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
- risk 0.64cvss 9.8epss 0.02
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
- risk 0.64cvss 9.8epss 0.03
In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.
- risk 0.64cvss 9.8epss 0.03
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign…
- risk 0.64cvss 9.8epss 0.07
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command…
- risk 0.64cvss 9.8epss 0.03
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.