VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 33 of 349
  • CVE-2023-46980CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

  • CVE-2023-46958CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.

  • CVE-2023-40050CriOct 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

  • CVE-2023-43792CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

  • CVE-2021-33635CriOct 29, 2023
    risk 0.64cvss 9.8epss 0.01

    When malicious images are pulled by isula pull, attackers can execute arbitrary code.

  • CVE-2023-46509CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

  • CVE-2023-46010CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

  • CVE-2023-30131CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.

  • CVE-2023-41630CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.

  • CVE-2023-29453CriOct 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…

  • CVE-2023-43625CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application…

  • CVE-2023-3656CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

  • CVE-2023-44011CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

  • CVE-2023-5201CriSep 30, 2023
    risk 0.64cvss 9.9epss 0.01

    The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]…

  • CVE-2023-43234CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2021-38243CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.

  • CVE-2023-43270CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.

  • CVE-2023-4291CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. …

  • CVE-2023-4994CriSep 16, 2023
    risk 0.64cvss 9.9epss 0.01

    The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.