VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 38 of 349
  • CVE-2022-25767CriMay 1, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

  • CVE-2021-39383CriMar 20, 2022
    risk 0.64cvss 9.8epss 0.03

    DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.

  • CVE-2022-25578CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.02

    taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.

  • CVE-2020-25197CriMar 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.

  • CVE-2020-15591CriMar 17, 2022
    risk 0.64cvss 9.8epss 0.04

    fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).

  • CVE-2022-25498CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

  • CVE-2022-22909HigMar 3, 2022
    risk 0.64cvss 8.8epss 0.45

    HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.

  • CVE-2022-24442CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.04

    JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

  • CVE-2022-24664CriFeb 16, 2022
    risk 0.64cvss 9.9epss 0.02

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

  • CVE-2021-46362CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.05

    A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

  • CVE-2021-44521CriFeb 11, 2022
    risk 0.64cvss 9.1epss 0.55

    When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would…

  • CVE-2021-44978CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

  • CVE-2021-45029CriJan 25, 2022
    risk 0.64cvss 9.8epss 0.06

    Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

  • CVE-2021-44734CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.06

    Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.

  • CVE-2021-39979CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.

  • CVE-2020-20601CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.08

    An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.

  • CVE-2021-44231CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.01

    Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2021-33816CriNov 10, 2021
    risk 0.64cvss 9.8epss 0.04

    The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

  • CVE-2021-43466CriNov 9, 2021
    risk 0.64cvss 9.8epss 0.04

    In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.

  • CVE-2021-38450CriOct 27, 2021
    risk 0.64cvss 9.9epss 0.01

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.