VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (4,559)

page 197 of 228
  • CVE-2015-1311Jan 22, 2015
    risk 0.00cvss epss 0.02

    The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2014-9521Jan 5, 2015
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to…

  • CVE-2014-2208Dec 28, 2014
    risk 0.00cvss epss 0.01

    CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

  • CVE-2014-9185Dec 19, 2014
    risk 0.00cvss epss 0.01

    Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.

  • CVE-2014-6261Dec 15, 2014
    risk 0.00cvss epss 0.03

    Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server or (2) deploying a crafted web site that is visited during a login session, aka ZEN-12657.

  • CVE-2014-7260Dec 12, 2014
    risk 0.00cvss epss 0.01

    The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives.

  • CVE-2014-7192Dec 11, 2014
    risk 0.00cvss epss 0.43

    Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

  • CVE-2014-8485Dec 9, 2014
    risk 0.00cvss epss 0.04

    The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.

  • CVE-2014-9280Dec 8, 2014
    risk 0.00cvss epss 0.01

    The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code via the filter parameter.

  • CVE-2014-9266Dec 8, 2014
    risk 0.00cvss epss 0.02

    The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2014-3065Dec 2, 2014
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the…

  • CVE-2014-8551Nov 26, 2014
    risk 0.00cvss epss 0.06

    The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

  • CVE-2014-0233Nov 16, 2014
    risk 0.00cvss epss 0.01

    Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme.

  • CVE-2012-2301Nov 16, 2014
    risk 0.00cvss epss 0.01

    The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.

  • CVE-2014-2177Nov 7, 2014
    risk 0.00cvss epss 0.01

    The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka…

  • CVE-2014-8661Nov 6, 2014
    risk 0.00cvss epss 0.04

    The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2014-8660Nov 6, 2014
    risk 0.00cvss epss 0.00

    SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.

  • CVE-2013-6399Nov 4, 2014
    risk 0.00cvss epss 0.02

    Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.

  • CVE-2013-4537Nov 4, 2014
    risk 0.00cvss epss 0.02

    The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

  • CVE-2013-4151Nov 4, 2014
    risk 0.00cvss epss 0.01

    The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.