VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 12 of 349
  • CVE-2023-6248CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data…

  • CVE-2023-46731CriNov 6, 2023
    risk 0.65cvss 10.0epss 0.89

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows any user with read access to the document…

  • CVE-2023-46404CriNov 3, 2023
    risk 0.65cvss 9.9epss 0.02

    PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

  • CVE-2023-33831CriSep 18, 2023
    risk 0.65cvss 9.8epss 0.23

    A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2023-37470CriAug 4, 2023
    risk 0.65cvss 10.0epss 0.01

    Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue…

  • CVE-2023-36255HigAug 3, 2023
    risk 0.65cvss 8.8epss 0.53

    An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.

  • CVE-2023-25910CriJun 13, 2023
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions < V5.7 SP2 HF1), SIMATIC STEP 7 V5 (All versions < V5.7). The affected product contains a database management system that…

  • CVE-2022-46161CriDec 6, 2022
    risk 0.65cvss 10.0epss 0.02

    pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running…

  • CVE-2022-44088CriNov 10, 2022
    risk 0.65cvss 9.8epss 0.20

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.

  • CVE-2021-26729CriOct 24, 2022
    risk 0.65cvss 10.0epss 0.02

    Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard…

  • CVE-2021-26728CriOct 24, 2022
    risk 0.65cvss 10.0epss 0.02

    Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware…

  • CVE-2021-26727CriOct 24, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A…

  • CVE-2021-27446CriMay 16, 2022
    risk 0.65cvss 10.0epss 0.03

    The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.

  • CVE-2022-29307CriMay 12, 2022
    risk 0.65cvss 9.8epss 0.18

    IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.

  • CVE-2022-24665CriFeb 16, 2022
    risk 0.65cvss 9.9epss 0.03

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

  • CVE-2022-24663CriFeb 16, 2022
    risk 0.65cvss 9.9epss 0.02

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

  • CVE-2021-27602CriApr 13, 2021
    risk 0.65cvss 9.9epss 0.02

    SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject…

  • CVE-2021-23281CriApr 13, 2021
    risk 0.65cvss 10.0epss 0.02

    Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to…

  • CVE-2021-25283CriFeb 27, 2021
    risk 0.65cvss 9.8epss 0.11

    An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.

  • CVE-2020-26943CriOct 16, 2020
    risk 0.65cvss 9.9epss 0.03

    An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used).…