CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 41 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-10257 | Cri | 0.64 | 9.8 | 0.09 | Mar 10, 2020 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe… | ||
| CVE-2020-8132 | Cri | 0.64 | 9.8 | 0.02 | Feb 28, 2020 | Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input. | ||
| CVE-2020-9406 | Cri | 0.64 | 9.8 | 0.01 | Feb 26, 2020 | IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. | ||
| CVE-2020-8129 | Cri | 0.64 | 9.8 | 0.03 | Feb 14, 2020 | An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code. | ||
| CVE-2019-17268 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2020 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. | ||
| CVE-2019-20343 | Cri | 0.64 | 9.8 | 0.02 | Jan 6, 2020 | The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an… | ||
| CVE-2019-15597 | Cri | 0.64 | 9.8 | 0.03 | Dec 18, 2019 | A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. | ||
| CVE-2019-10769 | Cri | 0.64 | 9.8 | 0.03 | Dec 6, 2019 | safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError. | ||
| CVE-2019-16885 | Cri | 0.64 | 9.8 | 0.05 | Dec 3, 2019 | In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via… | ||
| CVE-2019-5509 | Cri | 0.64 | 9.8 | 0.02 | Nov 21, 2019 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account. | ||
| CVE-2013-1666 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2019 | Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | ||
| CVE-2019-10211 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2019 | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. | ||
| CVE-2019-17526 | Cri | 0.64 | 9.8 | 0.03 | Oct 18, 2019 | An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an… | ||
| CVE-2019-17613 | Cri | 0.64 | 9.8 | 0.03 | Oct 15, 2019 | qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as… | ||
| CVE-2019-10759 | Cri | 0.64 | 9.9 | 0.02 | Oct 15, 2019 | safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. | ||
| CVE-2019-17408 | Cri | 0.64 | 9.8 | 0.04 | Oct 14, 2019 | parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr. | ||
| CVE-2019-15746 | Cri | 0.64 | 9.8 | 0.02 | Oct 7, 2019 | SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user. | ||
| CVE-2019-13558 | Cri | 0.64 | 9.8 | 0.03 | Sep 18, 2019 | In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash. | ||
| CVE-2018-21005 | Cri | 0.64 | 9.8 | 0.02 | Aug 27, 2019 | The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. | ||
| CVE-2019-15318 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. |
- risk 0.64cvss 9.8epss 0.09
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe…
- risk 0.64cvss 9.8epss 0.02
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
- risk 0.64cvss 9.8epss 0.01
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
- risk 0.64cvss 9.8epss 0.03
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.02
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.
- risk 0.64cvss 9.8epss 0.02
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an…
- risk 0.64cvss 9.8epss 0.03
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
- risk 0.64cvss 9.8epss 0.03
safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.
- risk 0.64cvss 9.8epss 0.05
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via…
- risk 0.64cvss 9.8epss 0.02
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.
- risk 0.64cvss 9.8epss 0.02
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
- risk 0.64cvss 9.8epss 0.02
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an…
- risk 0.64cvss 9.8epss 0.03
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as…
- risk 0.64cvss 9.9epss 0.02
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.04
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
- risk 0.64cvss 9.8epss 0.02
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.
- risk 0.64cvss 9.8epss 0.03
In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may allow remote code execution, data exfiltration, or cause a system crash.
- risk 0.64cvss 9.8epss 0.02
The bbp-move-topics plugin before 1.1.6 for WordPress has code injection.
- risk 0.64cvss 9.8epss 0.02
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.