CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Description
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-10 · CAPEC-101 · CAPEC-105 · CAPEC-108 · CAPEC-120 · CAPEC-13 · CAPEC-135 · CAPEC-14 · CAPEC-24 · CAPEC-250 · CAPEC-267 · CAPEC-273 · CAPEC-28 · CAPEC-3 · CAPEC-34 · CAPEC-42 · CAPEC-43 · CAPEC-45 · CAPEC-46 · CAPEC-47 · CAPEC-51 · CAPEC-52 · CAPEC-53 · CAPEC-6 · CAPEC-64 · CAPEC-67 · CAPEC-7 · CAPEC-71 · CAPEC-72 · CAPEC-76 · CAPEC-78 · CAPEC-79 · CAPEC-8 · CAPEC-80 · CAPEC-83 · CAPEC-84 · CAPEC-9
CVEs mapped to this weakness (5,475)
page 8 of 274| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20409 | Cri | 0.64 | 9.8 | 0.02 | Jun 23, 2020 | The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability. | ||
| CVE-2020-1961 | Cri | 0.64 | 9.8 | 0.05 | May 4, 2020 | Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered. | ||
| CVE-2020-7489 | Cri | 0.64 | 9.8 | 0.02 | Apr 22, 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this… | ||
| CVE-2018-21051 | Cri | 0.64 | 9.8 | 0.01 | Apr 8, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018). | ||
| CVE-2017-18652 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017). | ||
| CVE-2020-7635 | Cri | 0.64 | 9.8 | 0.04 | Apr 6, 2020 | compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument. | ||
| CVE-2020-7475 | Cri | 0.64 | 9.8 | 0.02 | Mar 23, 2020 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to… | ||
| CVE-2013-7487 | Cri | 0.64 | 9.8 | 0.03 | Mar 21, 2020 | On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000. | ||
| CVE-2013-1437 | Cri | 0.64 | 9.8 | 0.03 | Jan 28, 2020 | Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value. | ||
| CVE-2013-7380 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2020 | The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability | ||
| CVE-2013-2095 | Cri | 0.64 | 9.8 | 0.03 | Dec 10, 2019 | rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection | ||
| CVE-2011-2717 | Cri | 0.64 | 9.8 | 0.04 | Nov 27, 2019 | The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. | ||
| CVE-2019-19330 | Cri | 0.64 | 9.8 | 0.04 | Nov 27, 2019 | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks. | ||
| CVE-2014-3700 | Cri | 0.64 | 9.8 | 0.03 | Nov 21, 2019 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | ||
| CVE-2005-3056 | Cri | 0.64 | 9.8 | 0.03 | Nov 1, 2019 | TWiki allows arbitrary shell command execution via the Include function | ||
| CVE-2019-9535 | Cri | 0.64 | 9.8 | 0.02 | Oct 9, 2019 | A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an… | ||
| CVE-2017-18634 | Cri | 0.64 | 9.8 | 0.02 | Sep 16, 2019 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | ||
| CVE-2019-10074 | Cri | 0.64 | 9.8 | 0.03 | Sep 11, 2019 | An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good… | ||
| CVE-2017-18605 | Cri | 0.64 | 9.8 | 0.02 | Sep 10, 2019 | The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection. | ||
| CVE-2019-10665 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered… |
- risk 0.64cvss 9.8epss 0.02
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability.
- risk 0.64cvss 9.8epss 0.05
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discovered.
- risk 0.64cvss 9.8epss 0.02
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this…
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is an invalid free in the fingerprint Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2018-12853 (October 2018).
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).
- risk 0.64cvss 9.8epss 0.04
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
- risk 0.64cvss 9.8epss 0.02
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to…
- risk 0.64cvss 9.8epss 0.03
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000.
- risk 0.64cvss 9.8epss 0.03
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
- risk 0.64cvss 9.8epss 0.02
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
- risk 0.64cvss 9.8epss 0.03
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
- risk 0.64cvss 9.8epss 0.04
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
- risk 0.64cvss 9.8epss 0.04
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
- risk 0.64cvss 9.8epss 0.03
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
- risk 0.64cvss 9.8epss 0.03
TWiki allows arbitrary shell command execution via the Include function
- risk 0.64cvss 9.8epss 0.02
A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an…
- risk 0.64cvss 9.8epss 0.02
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
- risk 0.64cvss 9.8epss 0.03
An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been disabled on such a field. This was the case for the Customer Request "story" input in the Order Manager application. Encoding should not be disabled without good…
- risk 0.64cvss 9.8epss 0.02
The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered…