VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 86 of 350
  • CVE-2015-5243CriAug 20, 2018
    risk 0.57cvss 9.8epss 0.06

    phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.

  • CVE-2018-14910HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF.

  • CVE-2018-7748HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.03

    report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.

  • CVE-2018-1999023HigJul 23, 2018
    risk 0.57cvss 8.8epss 0.02

    The Battle for Wesnoth Project version 1.7.0 through 1.14.3 contains a Code Injection vulnerability in the Lua scripting engine that can result in code execution outside the sandbox. This attack appear to be exploitable via Loading specially-crafted saved games, networked games,…

  • CVE-2018-14421HigJul 20, 2018
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v6.61 allows Remote Code execution by placing PHP code in a movie picture address (aka v_pic) to /admin/admin_video.php (aka /backend/admin_video.php). The code is executed by visiting /details/index.php. This can also be exploited through CSRF.

  • CVE-2018-2427HigJul 10, 2018
    risk 0.57cvss 8.8epss 0.02

    SAP BusinessObjects Business Intelligence Suite, versions 4.10 and 4.20, and SAP Crystal Reports (version for Visual Studio .NET, Version 2010) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the…

  • CVE-2018-12995HigJun 29, 2018
    risk 0.57cvss 8.8epss 0.01

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.

  • CVE-2018-12994HigJun 29, 2018
    risk 0.57cvss 8.8epss 0.01

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.

  • CVE-2017-7798HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.02

    The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects…

  • CVE-2017-16100CriJun 7, 2018
    risk 0.57cvss 9.8epss 0.05

    dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.

  • CVE-2017-16042CriJun 4, 2018
    risk 0.57cvss 9.8epss 0.04

    Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

  • CVE-2018-7951HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may…

  • CVE-2018-7950HigJun 1, 2018
    risk 0.57cvss 8.8epss 0.01

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may…

  • CVE-2018-1104HigMay 2, 2018
    risk 0.57cvss 8.8epss 0.03

    Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

  • CVE-2018-8097CriMar 14, 2018
    risk 0.57cvss 9.8epss 0.06

    io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

  • CVE-2018-2363HigJan 9, 2018
    risk 0.57cvss 8.8epss 0.02

    SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially…

  • CVE-2017-14198HigNov 30, 2017
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.

  • CVE-2017-1001002CriNov 27, 2017
    risk 0.57cvss 9.8epss 0.02

    math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.

  • CVE-2017-16664HigNov 21, 2017
    risk 0.57cvss 8.8epss 0.02

    Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.

  • CVE-2017-15806HigNov 15, 2017
    risk 0.57cvss 8.1epss 0.11

    The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as…