VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 84 of 350
  • CVE-2020-5593HigJun 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.

  • CVE-2020-8149CriMay 15, 2020
    risk 0.57cvss 9.8epss 0.02

    Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

  • CVE-2020-6262HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…

  • CVE-2020-6243HigMay 12, 2020
    risk 0.57cvss 8.8epss 0.01

    Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted…

  • CVE-2020-7609CriApr 27, 2020
    risk 0.57cvss 9.8epss 0.02

    node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.

  • CVE-2020-5558HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.02

    CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.

  • CVE-2020-8141HigMar 15, 2020
    risk 0.57cvss 8.8epss 0.02

    The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.

  • CVE-2020-5203CriMar 11, 2020
    risk 0.57cvss 9.8epss 0.02

    In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method.

  • CVE-2013-4225HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content"…

  • CVE-2011-4943CriJan 22, 2020
    risk 0.57cvss 9.8epss 0.02

    ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)

  • CVE-2020-6836CriJan 11, 2020
    risk 0.57cvss 9.8epss 0.02

    grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from…

  • CVE-2019-20155HigJan 5, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server.

  • CVE-2019-19909HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.

  • CVE-2019-7486HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.02

    Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.

  • CVE-2019-15599CriDec 18, 2019
    risk 0.57cvss 9.8epss 0.03

    A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

  • CVE-2019-15598CriDec 18, 2019
    risk 0.57cvss 9.8epss 0.03

    A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.

  • CVE-2019-19010CriNov 16, 2019
    risk 0.57cvss 9.8epss 0.02

    Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.

  • CVE-2019-17308HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.

  • CVE-2019-17305HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.

  • CVE-2019-17303HigOct 7, 2019
    risk 0.57cvss 8.8epss 0.01

    SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.