VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 35 of 349
  • CVE-2023-38198CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

  • CVE-2023-29382CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

  • CVE-2021-31635CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.

  • CVE-2023-35150CriJun 23, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to…

  • CVE-2023-35034CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.

  • CVE-2023-29404CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…

  • CVE-2023-29402CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules…

  • CVE-2023-25953CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is…

  • CVE-2023-29861CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.

  • CVE-2023-29862CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.

  • CVE-2022-47129CriMay 11, 2023
    risk 0.64cvss 9.8epss 0.01

    PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.

  • CVE-2023-30349CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.02

    JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

  • CVE-2023-30404CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.

  • CVE-2020-29007CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.02

    The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary…

  • CVE-2023-27650CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

  • CVE-2023-24538CriApr 6, 2023
    risk 0.64cvss 9.8epss 0.02

    Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…

  • CVE-2023-25261CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an…

  • CVE-2023-24795CriMar 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.

  • CVE-2023-25344CriMar 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function.

  • CVE-2023-22889CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.