VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 60 of 349
  • CVE-2023-2583CriMay 8, 2023
    risk 0.58cvss 10.0epss 0.01

    Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.

  • CVE-2023-1283CriMar 8, 2023
    risk 0.58cvss 10.0epss 0.01

    Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

  • CVE-2022-46742CriDec 7, 2022
    risk 0.58cvss 10.0epss 0.01

    Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

  • CVE-2022-25759CriJul 22, 2022
    risk 0.58cvss 9.9epss 0.11

    The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

  • CVE-2021-41749CriJun 12, 2022
    risk 0.58cvss 9.8epss 0.18

    In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.

  • CVE-2022-23332HigMay 9, 2022
    risk 0.58cvss 8.8epss 0.05

    Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.

  • CVE-2021-34994HigJan 13, 2022
    risk 0.58cvss 8.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2021-22053HigNov 19, 2021
    risk 0.58cvss 8.8epss 0.13

    Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the…

  • CVE-2021-41269CriNov 15, 2021
    risk 0.58cvss 10.0epss 0.04

    cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to…

  • CVE-2021-29472HigApr 27, 2021
    risk 0.58cvss 8.8epss 0.05

    Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercurial is installed on the system.…

  • CVE-2020-5739HigApr 14, 2020
    risk 0.58cvss 8.8epss 0.05

    Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is…

  • CVE-2014-5013HigJan 10, 2020
    risk 0.58cvss 8.8epss 0.04

    DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

  • CVE-2019-14867HigNov 27, 2019
    risk 0.58cvss 8.8epss 0.07

    A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker…

  • CVE-2019-10760CriOct 15, 2019
    risk 0.58cvss 9.9epss 0.03

    safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.

  • CVE-2019-10431CriOct 1, 2019
    risk 0.58cvss 9.9epss 0.03

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constructors allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-15873HigSep 3, 2019
    risk 0.58cvss 8.8epss 0.04

    The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.

  • CVE-2019-15647HigAug 27, 2019
    risk 0.58cvss 8.8epss 0.05

    The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.

  • CVE-2019-0193HigKEVAug 1, 2019
    risk 0.58cvss 7.2epss 0.84

    In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow…

  • CVE-2019-14271CriJul 29, 2019
    risk 0.58cvss 9.8epss 0.19

    In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

  • CVE-2019-7580HigFeb 7, 2019
    risk 0.58cvss 8.8epss 0.10

    ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.