VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,044)

page 133 of 353
  • CVE-2023-30912HigOct 25, 2023
    risk 0.47cvss 7.2epss 0.01

    A remote code execution issue exists in HPE OneView.

  • CVE-2023-36789HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.02

    Skype for Business Remote Code Execution Vulnerability

  • CVE-2023-44847HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

  • CVE-2023-37427HigAug 22, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary…

  • CVE-2023-36992HigJul 7, 2023
    risk 0.47cvss 7.2epss 0.01

    PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.

  • CVE-2020-20918HigJun 20, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.

  • CVE-2023-32540HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead…

  • CVE-2023-29963HigMay 5, 2023
    risk 0.47cvss 7.2epss 0.02

    S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.

  • CVE-2022-36963HigApr 21, 2023
    risk 0.47cvss 7.2epss 0.08

    The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.

  • CVE-2023-25550HigApr 18, 2023
    risk 0.47cvss 7.2epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center…

  • CVE-2023-25549HigApr 18, 2023
    risk 0.47cvss 7.2epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)

  • CVE-2023-30638HigApr 14, 2023
    risk 0.47cvss 7.2epss 0.01

    Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.

  • CVE-2023-24835HigMar 27, 2023
    risk 0.47cvss 7.2epss 0.01

    Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or…

  • CVE-2023-0575HigFeb 9, 2023
    risk 0.47cvss 7.2epss 0.01

    External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege…

  • CVE-2022-48093HigFeb 1, 2023
    risk 0.47cvss 7.2epss 0.01

    Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.

  • CVE-2022-48116HigJan 27, 2023
    risk 0.47cvss 7.2epss 0.01

    AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.

  • CVE-2022-44533HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43542HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43541HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43660HigDec 7, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are…