VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 43 of 349
  • CVE-2019-6713CriJan 23, 2019
    risk 0.64cvss 9.8epss 0.02

    app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.

  • CVE-2018-16168CriJan 9, 2019
    risk 0.64cvss 9.8epss 0.02

    LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.

  • CVE-2019-0247CriJan 8, 2019
    risk 0.64cvss 9.8epss 0.01

    SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.

  • CVE-2018-20605CriDec 30, 2018
    risk 0.64cvss 9.8epss 0.02

    imcat 4.4 allows remote attackers to execute arbitrary PHP code by using root/run/adm.php to modify the boot/bootskip.php file.

  • CVE-2018-20325CriDec 21, 2018
    risk 0.64cvss 9.8epss 0.03

    There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.

  • CVE-2018-1000881CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.04

    Traccar Traccar Server version 4.0 and earlier contains a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in ComputedAttributesHandler.java that can result in Remote Command Execution. This attack appear to be exploitable via Remote: web…

  • CVE-2018-20300CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file.

  • CVE-2018-20133CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    ymlref allows code injection.

  • CVE-2018-20027CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.02

    The yaml_parse.load method in Pylearn2 allows code injection.

  • CVE-2018-18249CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.01

    Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or…

  • CVE-2018-19595CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.04

    PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect…

  • CVE-2018-19220CriNov 12, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.

  • CVE-2018-19196CriNov 12, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an…

  • CVE-2018-19180CriNov 11, 2018
    risk 0.64cvss 9.8epss 0.02

    statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.

  • CVE-2018-18903CriNov 3, 2018
    risk 0.64cvss 9.8epss 0.05

    Vanilla 2.6.x before 2.6.4 allows remote code execution.

  • CVE-2018-6012CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.01

    The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.

  • CVE-2018-18892CriNov 1, 2018
    risk 0.64cvss 9.8epss 0.03

    MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.

  • CVE-2018-18835CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.02

    upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.

  • CVE-2018-18461CriOct 18, 2018
    risk 0.64cvss 9.8epss 0.04

    The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php.

  • CVE-2018-18319CriOct 15, 2018
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that…