VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 42 of 349
  • CVE-2019-15224CriAug 19, 2019
    risk 0.64cvss 9.8epss 0.04

    The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

  • CVE-2015-9298CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The events-manager plugin before 5.6 for WordPress has code injection.

  • CVE-2019-14746CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

  • CVE-2019-14282CriJul 26, 2019
    risk 0.64cvss 9.8epss 0.03

    The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

  • CVE-2019-14281CriJul 26, 2019
    risk 0.64cvss 9.8epss 0.03

    The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

  • CVE-2019-13956CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.05

    Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were used).

  • CVE-2019-6823CriJul 15, 2019
    risk 0.64cvss 9.8epss 0.05

    A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.

  • CVE-2019-13354CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.03

    The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.

  • CVE-2019-10100CriJul 3, 2019
    risk 0.64cvss 9.8epss 0.02

    In JetBrains YouTrack Confluence plugin versions before 1.8.1.3, it was possible to achieve Server Side Template Injection. The attacker could add an Issue macro to the page in Confluence, and use a combination of a valid id field and specially crafted code in the…

  • CVE-2019-9891CriMay 31, 2019
    risk 0.64cvss 9.8epss 0.03

    The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalation and execution of commands when used in a shell script called, for example, via sudo.

  • CVE-2019-10842CriApr 4, 2019
    risk 0.64cvss 9.8epss 0.05

    Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org. An unauthenticated attacker can craft the ___cfduid cookie value with base64 arbitrary code to be executed via eval(), which can be leveraged to execute…

  • CVE-2019-10684CriApr 1, 2019
    risk 0.64cvss 9.8epss 0.02

    Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.

  • CVE-2014-5401CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.05

    Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet…

  • CVE-2019-5413CriMar 21, 2019
    risk 0.64cvss 9.8epss 0.03

    An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

  • CVE-2019-9651CriMar 11, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. This occurs because some dangerous PHP functions (such as "eval") are blocked but others (such as…

  • CVE-2019-9227CriFeb 28, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_base.inc.php file.

  • CVE-2019-7720CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.02

    taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

  • CVE-2019-7719CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.02

    Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.

  • CVE-2018-20768CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.

  • CVE-2019-7692CriFeb 10, 2019
    risk 0.64cvss 9.8epss 0.02

    install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.