VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 41 of 349
  • CVE-2020-10257CriMar 10, 2020
    risk 0.64cvss 9.8epss 0.09

    The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…

  • CVE-2020-8132CriFeb 28, 2020
    risk 0.64cvss 9.8epss 0.02

    Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

  • CVE-2020-9406CriFeb 26, 2020
    risk 0.64cvss 9.8epss 0.01

    IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

  • CVE-2020-8129CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.03

    An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.

  • CVE-2019-17268CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.02

    The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

  • CVE-2019-20343CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.02

    The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an…

  • CVE-2019-15597CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.03

    A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.

  • CVE-2019-10769CriDec 6, 2019
    risk 0.64cvss 9.8epss 0.03

    safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.

  • CVE-2019-16885CriDec 3, 2019
    risk 0.64cvss 9.8epss 0.05

    In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via…

  • CVE-2019-5509CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.02

    ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.

  • CVE-2013-1666CriNov 1, 2019
    risk 0.64cvss 9.8epss 0.02

    Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

  • CVE-2019-10211CriOct 29, 2019
    risk 0.64cvss 9.8epss 0.02

    Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

  • CVE-2019-17526CriOct 18, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an…

  • CVE-2019-17613CriOct 15, 2019
    risk 0.64cvss 9.8epss 0.03

    qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as…

  • CVE-2019-10759CriOct 15, 2019
    risk 0.64cvss 9.9epss 0.02

    safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.

  • CVE-2019-17408CriOct 14, 2019
    risk 0.64cvss 9.8epss 0.04

    parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.

  • CVE-2019-15746CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.02

    SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.

  • CVE-2019-13558CriSep 18, 2019
    risk 0.64cvss 9.8epss 0.03

    In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.

  • CVE-2018-21005CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.

  • CVE-2019-15318CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.