VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 7 of 274
  • CVE-2021-34079CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.04

    OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.

  • CVE-2020-28246CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this…

  • CVE-2022-25420CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.03

    NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.

  • CVE-2022-26205CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.02

    Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.

  • CVE-2022-25337CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

  • CVE-2021-44530CriJan 14, 2022
    risk 0.64cvss 9.8epss 0.01

    An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.

  • CVE-2021-43185CriNov 9, 2021
    risk 0.64cvss 9.8epss 0.02

    JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

  • CVE-2021-38458CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-41862CriOct 2, 2021
    risk 0.64cvss 9.8epss 0.02

    AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (BCEL).

  • CVE-2021-41392CriSep 17, 2021
    risk 0.64cvss 9.8epss 0.03

    static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.

  • CVE-2021-20509CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 198243.

  • CVE-2020-17952CriJul 26, 2021
    risk 0.64cvss 9.8epss 0.02

    A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.

  • CVE-2021-3169CriJul 23, 2021
    risk 0.64cvss 9.8epss 0.03

    An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.

  • CVE-2021-27730CriMar 2, 2021
    risk 0.64cvss 9.8epss 0.01

    Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.

  • CVE-2020-7786CriFeb 8, 2021
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.

  • CVE-2020-7782CriFeb 8, 2021
    risk 0.64cvss 9.8epss 0.02

    This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.

  • CVE-2020-15690CriJan 30, 2021
    risk 0.64cvss 9.8epss 0.03

    In Nim before 1.2.6, the standard library asyncftpclient lacks a check for whether a message contains a newline character.

  • CVE-2020-21523CriSep 30, 2020
    risk 0.64cvss 9.8epss 0.03

    A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This file can cause arbitrary code execution when it is rendered in the background. exp: <#assign…

  • CVE-2020-14505CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.07

    Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command…

  • CVE-2020-8186CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.