VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 157 of 353
  • CVE-2024-2016MedMar 21, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The…

  • CVE-2024-1885MedFeb 26, 2024
    risk 0.41cvss 6.3epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

  • CVE-2023-5677MedFeb 5, 2024
    risk 0.41cvss 6.3epss 0.01

    Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or…

  • CVE-2024-0738MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The manipulation leads to code injection. The attack may be initiated…

  • CVE-2024-0196MedJan 2, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Magic-Api up to 2.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /resource/file/api/save?auto=1. The manipulation leads to code injection. The attack can be launched remotely. The exploit…

  • CVE-2023-26145HigSep 28, 2023
    risk 0.41cvss 7.4epss 0.03

    This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths…

  • CVE-2023-40621MedSep 12, 2023
    risk 0.41cvss 6.3epss 0.01

    SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt…

  • CVE-2023-27869MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.02

    IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property,…

  • CVE-2023-27868MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.02

    IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request…

  • CVE-2023-27867MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.02

    IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could…

  • CVE-2023-27866MedJun 28, 2023
    risk 0.41cvss 6.3epss 0.01

    IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.

  • CVE-2023-2056MedApr 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public…

  • CVE-2023-1947MedApr 7, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…

  • CVE-2022-3960MedApr 3, 2023
    risk 0.41cvss 6.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 

  • CVE-2023-1773MedMar 31, 2023
    risk 0.41cvss 6.3epss 0.02

    A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration File Handler. The manipulation leads to code injection. The attack can be initiated remotely. The…

  • CVE-2022-25926HigJan 4, 2023
    risk 0.41cvss 7.4epss 0.01

    Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.

  • CVE-2022-4300MedDec 6, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated remotely. The exploit has been disclosed…

  • CVE-2022-21797HigSep 26, 2022
    risk 0.41cvss 7.3epss 0.02

    The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

  • CVE-2022-36069HigSep 7, 2022
    risk 0.41cvss 7.3epss 0.01

    Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repository URL). When building the commands,…

  • CVE-2022-35847MedSep 6, 2022
    risk 0.41cvss 6.3epss 0.01

    An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a crafted payload.