CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 39 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-23037 | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2021 | Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request. | ||
| CVE-2021-22961 | Cri | 0.64 | 9.8 | 0.02 | Oct 18, 2021 | A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution. | ||
| CVE-2021-40499 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2021 | Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the… | ||
| CVE-2021-40889 | Cri | 0.64 | 9.8 | 0.02 | Oct 11, 2021 | CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject… | ||
| CVE-2020-21652 | Cri | 0.64 | 9.8 | 0.03 | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method. | ||
| CVE-2020-21651 | Cri | 0.64 | 9.8 | 0.03 | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method. | ||
| CVE-2021-40323 | Cri | 0.64 | 9.8 | 0.87 | Oct 4, 2021 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection. | ||
| CVE-2021-40373 | Cri | 0.64 | 9.8 | 0.05 | Sep 10, 2021 | playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI. | ||
| CVE-2021-29772 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2021 | IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774. | ||
| CVE-2021-40084 | Cri | 0.64 | 9.8 | 0.03 | Aug 25, 2021 | opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that. | ||
| CVE-2020-22937 | Cri | 0.64 | 9.8 | 0.03 | Aug 17, 2021 | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file. | ||
| CVE-2021-38196 | Cri | 0.64 | 9.8 | 0.03 | Aug 8, 2021 | An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose. | ||
| CVE-2020-18172 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2021 | A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. | ||
| CVE-2020-21784 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2021 | phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. | ||
| CVE-2020-35339 | Cri | 0.64 | 9.8 | 0.04 | Feb 17, 2021 | In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server. | ||
| CVE-2020-28870 | Cri | 0.64 | 9.8 | 0.03 | Feb 10, 2021 | In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php. | ||
| CVE-2021-25770 | Cri | 0.64 | 9.8 | 0.03 | Feb 3, 2021 | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. | ||
| CVE-2020-20298 | Cri | 0.64 | 9.8 | 0.03 | Dec 18, 2020 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. | ||
| CVE-2020-11851 | Cri | 0.64 | 9.8 | 0.03 | Nov 17, 2020 | Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code. | ||
| CVE-2020-7472 | Cri | 0.64 | 9.8 | 0.03 | Nov 12, 2020 | An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted… |
- risk 0.64cvss 9.8epss 0.01
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
- risk 0.64cvss 9.8epss 0.02
A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary code execution from a file in the user path on first execution.
- risk 0.64cvss 9.8epss 0.01
Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…
- risk 0.64cvss 9.8epss 0.02
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject…
- risk 0.64cvss 9.8epss 0.03
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
- risk 0.64cvss 9.8epss 0.03
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
- risk 0.64cvss 9.8epss 0.87
Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.
- risk 0.64cvss 9.8epss 0.05
playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.
- risk 0.64cvss 9.8epss 0.01
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
- risk 0.64cvss 9.8epss 0.03
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specification) does not do that.
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote attackers can execute arbitrary code via proc-macros, and otherwise has no legitimate purpose.
- risk 0.64cvss 9.8epss 0.01
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
- risk 0.64cvss 9.8epss 0.01
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
- risk 0.64cvss 9.8epss 0.04
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.
- risk 0.64cvss 9.8epss 0.03
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
- risk 0.64cvss 9.8epss 0.03
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
- risk 0.64cvss 9.8epss 0.03
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
- risk 0.64cvss 9.8epss 0.03
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.
- risk 0.64cvss 9.8epss 0.03
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted…