CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 43 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-6713 | Cri | 0.64 | 9.8 | 0.02 | Jan 23, 2019 | app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call. | ||
| CVE-2018-16168 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2019 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors. | ||
| CVE-2019-0247 | Cri | 0.64 | 9.8 | 0.01 | Jan 8, 2019 | SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | ||
| CVE-2018-20605 | Cri | 0.64 | 9.8 | 0.02 | Dec 30, 2018 | imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file. | ||
| CVE-2018-20325 | Cri | 0.64 | 9.8 | 0.03 | Dec 21, 2018 | There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution. | ||
| CVE-2018-1000881 | Cri | 0.64 | 9.8 | 0.04 | Dec 20, 2018 | Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web… | ||
| CVE-2018-20300 | Cri | 0.64 | 9.8 | 0.02 | Dec 20, 2018 | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file. | ||
| CVE-2018-20133 | Cri | 0.64 | 9.8 | 0.02 | Dec 17, 2018 | ymlref allows code injection. | ||
| CVE-2018-20027 | Cri | 0.64 | 9.8 | 0.02 | Dec 17, 2018 | The yaml_parse.load method in Pylearn2 allows code injection. | ||
| CVE-2018-18249 | Cri | 0.64 | 9.8 | 0.01 | Dec 17, 2018 | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or… | ||
| CVE-2018-19595 | Cri | 0.64 | 9.8 | 0.04 | Nov 27, 2018 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect… | ||
| CVE-2018-19220 | Cri | 0.64 | 9.8 | 0.02 | Nov 12, 2018 | An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. | ||
| CVE-2018-19196 | Cri | 0.64 | 9.8 | 0.03 | Nov 12, 2018 | An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an… | ||
| CVE-2018-19180 | Cri | 0.64 | 9.8 | 0.02 | Nov 11, 2018 | statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php. | ||
| CVE-2018-18903 | Cri | 0.64 | 9.8 | 0.05 | Nov 3, 2018 | Vanilla 2.6.x before 2.6.4 allows remote code execution. | ||
| CVE-2018-6012 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2018 | The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function. | ||
| CVE-2018-18892 | Cri | 0.64 | 9.8 | 0.03 | Nov 1, 2018 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | ||
| CVE-2018-18835 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2018 | upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file. | ||
| CVE-2018-18461 | Cri | 0.64 | 9.8 | 0.04 | Oct 18, 2018 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php. | ||
| CVE-2018-18319 | Cri | 0.64 | 9.8 | 0.05 | Oct 15, 2018 | An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that… |
- risk 0.64cvss 9.8epss 0.02
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.
- risk 0.64cvss 9.8epss 0.02
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
- risk 0.64cvss 9.8epss 0.01
SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- risk 0.64cvss 9.8epss 0.02
imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.
- risk 0.64cvss 9.8epss 0.03
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.
- risk 0.64cvss 9.8epss 0.04
Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web…
- risk 0.64cvss 9.8epss 0.02
Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.
- risk 0.64cvss 9.8epss 0.02
ymlref allows code injection.
- risk 0.64cvss 9.8epss 0.02
The yaml_parse.load method in Pylearn2 allows code injection.
- risk 0.64cvss 9.8epss 0.01
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or…
- risk 0.64cvss 9.8epss 0.04
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
- risk 0.64cvss 9.8epss 0.03
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an…
- risk 0.64cvss 9.8epss 0.02
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
- risk 0.64cvss 9.8epss 0.05
Vanilla 2.6.x before 2.6.4 allows remote code execution.
- risk 0.64cvss 9.8epss 0.01
The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
- risk 0.64cvss 9.8epss 0.03
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
- risk 0.64cvss 9.8epss 0.02
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
- risk 0.64cvss 9.8epss 0.04
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.
- risk 0.64cvss 9.8epss 0.05
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that…