VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 56 of 349
  • CVE-2023-1287CriMar 9, 2023
    risk 0.59cvss 9.0epss 0.01

    An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

  • CVE-2022-46836CriFeb 20, 2023
    risk 0.59cvss 9.1epss 0.01

    PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

  • CVE-2023-23551CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2022-42699CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

  • CVE-2021-26731CriOct 24, 2022
    risk 0.59cvss 9.1epss 0.02

    Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc…

  • CVE-2022-36386CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

  • CVE-2022-29078CriApr 25, 2022
    risk 0.59cvss 9.8epss 0.33

    The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is…

  • CVE-2022-0811HigMar 16, 2022
    risk 0.59cvss 8.8epss 0.19

    A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the…

  • CVE-2022-24295HigFeb 21, 2022
    risk 0.59cvss 8.8epss 0.17

    Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

  • CVE-2021-46063CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.03

    MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

  • CVE-2022-23631CriFeb 9, 2022
    risk 0.59cvss 9.0epss 0.02

    superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the…

  • CVE-2021-37079CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.

  • CVE-2021-31630HigAug 3, 2021
    risk 0.59cvss 8.8epss 0.27

    Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.

  • CVE-2021-32924HigJun 1, 2021
    risk 0.59cvss 8.8epss 0.20

    Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.

  • CVE-2020-28905HigMay 24, 2021
    risk 0.59cvss 8.8epss 0.26

    Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

  • CVE-2020-15227HigOct 1, 2020
    risk 0.59cvss 8.7epss 0.34

    Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.

  • CVE-2020-12013CriJul 16, 2020
    risk 0.59cvss 9.1epss 0.03

    A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A…

  • CVE-2019-18889CriNov 21, 2019
    risk 0.59cvss 9.8epss 0.33

    An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

  • CVE-2019-9848CriJul 17, 2019
    risk 0.59cvss 9.8epss 0.31

    LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into…

  • CVE-2019-0330CriJul 10, 2019
    risk 0.59cvss 9.1epss 0.02

    The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.