VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 40 of 349
  • CVE-2020-8349CriOct 14, 2020
    risk 0.64cvss 9.8epss 0.02

    An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is…

  • CVE-2020-18185CriOct 2, 2020
    risk 0.64cvss 9.8epss 0.02

    class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.

  • CVE-2020-15371CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, v8.2.2c, v8.2.1e, v8.1.2k, v8.2.0_CBN3, contains code injection and privilege escalation vulnerability.

  • CVE-2020-6144CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.06

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to…

  • CVE-2020-6143CriSep 1, 2020
    risk 0.64cvss 9.8epss 0.06

    A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An attacker can send an HTTP request to…

  • CVE-2020-15865CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.05

    A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully…

  • CVE-2020-10055CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.06

    A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting…

  • CVE-2020-9664CriJul 22, 2020
    risk 0.64cvss 9.8epss 0.08

    Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-15348CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/delete_cpes_by_ids?cpe_ids= for eval injection of Python code.

  • CVE-2020-7675CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.

  • CVE-2020-7674CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.

  • CVE-2020-7673CriJun 10, 2020
    risk 0.64cvss 9.8epss 0.03

    node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.

  • CVE-2020-8180CriJun 8, 2020
    risk 0.64cvss 9.9epss 0.02

    A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.

  • CVE-2019-5997CriMay 20, 2020
    risk 0.64cvss 9.8epss 0.02

    Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.

  • CVE-2020-10176CriMay 7, 2020
    risk 0.64cvss 9.8epss 0.02

    ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.

  • CVE-2020-10948CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.07

    Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.

  • CVE-2019-9163CriApr 1, 2020
    risk 0.64cvss 9.8epss 0.02

    The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

  • CVE-2020-5553CriMar 25, 2020
    risk 0.64cvss 9.8epss 0.02

    mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

  • CVE-2020-7480CriMar 23, 2020
    risk 0.64cvss 9.8epss 0.02

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.

  • CVE-2020-8137CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.04

    Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.