CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (4,559)
page 197 of 228| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-1311 | 0.00 | — | 0.02 | Jan 22, 2015 | The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||
| CVE-2014-9521 | 0.00 | — | 0.02 | Jan 5, 2015 | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to… | |||
| CVE-2014-2208 | 0.00 | — | 0.01 | Dec 28, 2014 | CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string. | |||
| CVE-2014-9185 | 0.00 | — | 0.01 | Dec 19, 2014 | Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter. | |||
| CVE-2014-6261 | 0.00 | — | 0.03 | Dec 15, 2014 | Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server or (2) deploying a crafted web site that is visited during a login session, aka ZEN-12657. | |||
| CVE-2014-7260 | 0.00 | — | 0.01 | Dec 12, 2014 | The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives. | |||
| CVE-2014-7192 | 0.00 | — | 0.43 | Dec 11, 2014 | Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file. | |||
| CVE-2014-8485 | 0.00 | — | 0.04 | Dec 9, 2014 | The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file. | |||
| CVE-2014-9280 | 0.00 | — | 0.01 | Dec 8, 2014 | The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code via the filter parameter. | |||
| CVE-2014-9266 | 0.00 | — | 0.02 | Dec 8, 2014 | The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors. | |||
| CVE-2014-3065 | 0.00 | — | 0.00 | Dec 2, 2014 | Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the… | |||
| CVE-2014-8551 | 0.00 | — | 0.06 | Nov 26, 2014 | The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets. | |||
| CVE-2014-0233 | 0.00 | — | 0.01 | Nov 16, 2014 | Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme. | |||
| CVE-2012-2301 | 0.00 | — | 0.01 | Nov 16, 2014 | The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors. | |||
| CVE-2014-2177 | 0.00 | — | 0.01 | Nov 7, 2014 | The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka… | |||
| CVE-2014-8661 | 0.00 | — | 0.04 | Nov 6, 2014 | The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors. | |||
| CVE-2014-8660 | 0.00 | — | 0.00 | Nov 6, 2014 | SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors. | |||
| CVE-2013-6399 | 0.00 | — | 0.02 | Nov 4, 2014 | Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image. | |||
| CVE-2013-4537 | 0.00 | — | 0.02 | Nov 4, 2014 | The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image. | |||
| CVE-2013-4151 | 0.00 | — | 0.01 | Nov 4, 2014 | The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write. |
- CVE-2015-1311Jan 22, 2015risk 0.00cvss —epss 0.02
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- CVE-2014-9521Jan 5, 2015risk 0.00cvss —epss 0.02
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, then accessing it via a direct request to…
- CVE-2014-2208Dec 28, 2014risk 0.00cvss —epss 0.01
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.
- CVE-2014-9185Dec 19, 2014risk 0.00cvss —epss 0.01
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
- CVE-2014-6261Dec 15, 2014risk 0.00cvss —epss 0.03
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server or (2) deploying a crafted web site that is visited during a login session, aka ZEN-12657.
- CVE-2014-7260Dec 12, 2014risk 0.00cvss —epss 0.01
The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives.
- CVE-2014-7192Dec 11, 2014risk 0.00cvss —epss 0.43
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
- CVE-2014-8485Dec 9, 2014risk 0.00cvss —epss 0.04
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
- CVE-2014-9280Dec 8, 2014risk 0.00cvss —epss 0.01
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code via the filter parameter.
- CVE-2014-9266Dec 8, 2014risk 0.00cvss —epss 0.02
The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2014-3065Dec 2, 2014risk 0.00cvss —epss 0.00
Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the…
- CVE-2014-8551Nov 26, 2014risk 0.00cvss —epss 0.06
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.
- CVE-2014-0233Nov 16, 2014risk 0.00cvss —epss 0.01
Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme.
- CVE-2012-2301Nov 16, 2014risk 0.00cvss —epss 0.01
The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.
- CVE-2014-2177Nov 7, 2014risk 0.00cvss —epss 0.01
The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka…
- CVE-2014-8661Nov 6, 2014risk 0.00cvss —epss 0.04
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2014-8660Nov 6, 2014risk 0.00cvss —epss 0.00
SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.
- CVE-2013-6399Nov 4, 2014risk 0.00cvss —epss 0.02
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.
- CVE-2013-4537Nov 4, 2014risk 0.00cvss —epss 0.02
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.
- CVE-2013-4151Nov 4, 2014risk 0.00cvss —epss 0.01
The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.