VYPR

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ClassIncompleteLikelihood: High

Description

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9

CVEs mapped to this weakness (5,475)

page 8 of 274
  • CVE-2019-20409CriJun 23, 2020
    risk 0.64cvss 9.8epss 0.02

    The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.

  • CVE-2020-1961CriMay 4, 2020
    risk 0.64cvss 9.8epss 0.05

    Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.

  • CVE-2020-7489CriApr 22, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this…

  • CVE-2018-21051CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018).

  • CVE-2017-18652CriApr 7, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).

  • CVE-2020-7635CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.04

    compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.

  • CVE-2020-7475CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to…

  • CVE-2013-7487CriMar 21, 2020
    risk 0.64cvss 9.8epss 0.03

    On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000.

  • CVE-2013-1437CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

  • CVE-2013-7380CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.02

    The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability

  • CVE-2013-2095CriDec 10, 2019
    risk 0.64cvss 9.8epss 0.03

    rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection

  • CVE-2011-2717CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.04

    The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.

  • CVE-2019-19330CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.04

    The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

  • CVE-2014-3700CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.03

    eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data

  • CVE-2005-3056CriNov 1, 2019
    risk 0.64cvss 9.8epss 0.03

    TWiki allows arbitrary shell command execution via the Include function

  • CVE-2019-9535CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an…

  • CVE-2017-18634CriSep 16, 2019
    risk 0.64cvss 9.8epss 0.02

    The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.

  • CVE-2019-10074CriSep 11, 2019
    risk 0.64cvss 9.8epss 0.03

    An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good…

  • CVE-2017-18605CriSep 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.

  • CVE-2019-10665CriSep 9, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered…