VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 83 of 350
  • CVE-2021-36800HigAug 4, 2021
    risk 0.57cvss 8.7epss 0.01

    Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function is executed directly. This issue was…

  • CVE-2021-32706HigAug 4, 2021
    risk 0.57cvss 7.6epss 0.60

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code,…

  • CVE-2017-18113HigAug 2, 2021
    risk 0.57cvss 8.8epss 0.02

    The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The…

  • CVE-2021-32756HigJul 21, 2021
    risk 0.57cvss 8.8epss 0.02

    ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string which would be evaluated. Successful exploitation will…

  • CVE-2021-23390CriJul 12, 2021
    risk 0.57cvss 9.8epss 0.03

    The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

  • CVE-2021-23389CriJul 12, 2021
    risk 0.57cvss 9.8epss 0.04

    The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

  • CVE-2020-23219HigJul 1, 2021
    risk 0.57cvss 8.8epss 0.02

    Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.

  • CVE-2021-27903CriJun 30, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).

  • CVE-2021-35514CriJun 28, 2021
    risk 0.57cvss 9.8epss 0.01

    Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.

  • CVE-2020-22201HigJun 16, 2021
    risk 0.57cvss 8.8epss 0.01

    phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.

  • CVE-2021-1362HigApr 8, 2021
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow…

  • CVE-2021-27438HigMar 25, 2021
    risk 0.57cvss 8.8epss 0.01

    The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).

  • CVE-2021-28834CriMar 19, 2021
    risk 0.57cvss 9.8epss 0.03

    Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.

  • CVE-2021-27230HigMar 15, 2021
    risk 0.57cvss 8.8epss 0.03

    ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.

  • CVE-2021-23344CriMar 4, 2021
    risk 0.57cvss 9.8epss 0.05

    The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

  • CVE-2021-26551HigFeb 9, 2021
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.

  • CVE-2021-21466HigJan 12, 2021
    risk 0.57cvss 8.8epss 0.03

    SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious…

  • CVE-2020-24628HigOct 2, 2020
    risk 0.57cvss 8.8epss 0.01

    A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

  • CVE-2020-15070HigAug 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Zulip Server 2.x before 2.1.7 allows eval injection if a privileged attacker were able to write directly to the postgres database, and chose to write a crafted custom profile field value.

  • CVE-2016-11064CriJun 19, 2020
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.