VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 27 of 349
  • CVE-2024-6596CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

  • CVE-2024-44411CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.04

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

  • CVE-2024-44410CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

  • CVE-2024-39714CriSep 7, 2024
    risk 0.64cvss 9.9epss 0.01

    A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

  • CVE-2024-45507CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.93

    Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

  • CVE-2024-45623CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no…

  • CVE-2024-41369CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php

  • CVE-2024-41368CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php

  • CVE-2024-41367CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

  • CVE-2024-41366CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php

  • CVE-2024-41364CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php

  • CVE-2024-41361CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

  • CVE-2024-7720CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.01

    HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.

  • CVE-2024-42634CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.

  • CVE-2024-41623CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

  • CVE-2024-22116CriAug 12, 2024
    risk 0.64cvss 9.9epss 0.02

    An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising…

  • CVE-2024-42393CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-41468CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.05

    Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

  • CVE-2024-21552CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

  • CVE-2024-39962CriJul 19, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.