VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 87 of 350
  • CVE-2014-4000HigNov 15, 2017
    risk 0.57cvss 8.8epss 0.02

    Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).

  • CVE-2017-16764CriNov 10, 2017
    risk 0.57cvss 9.8epss 0.04

    An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to…

  • CVE-2015-6576HigOct 3, 2017
    risk 0.57cvss 8.8epss 0.04

    Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

  • CVE-2017-14764HigSep 27, 2017
    risk 0.57cvss 8.8epss 0.02

    In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

  • CVE-2017-14146HigSep 5, 2017
    risk 0.57cvss 8.8epss 0.01

    HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.

  • CVE-2017-1440HigAug 30, 2017
    risk 0.57cvss 8.8epss 0.03

    IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable…

  • CVE-2017-10844HigAug 29, 2017
    risk 0.57cvss 8.8epss 0.01

    baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

  • CVE-2017-10835HigAug 29, 2017
    risk 0.57cvss 8.8epss 0.01

    "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.

  • CVE-2011-0469CriAug 17, 2017
    risk 0.57cvss 9.8epss 0.02

    Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.

  • CVE-2017-11760HigJul 31, 2017
    risk 0.57cvss 8.8epss 0.01

    uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area.

  • CVE-2017-11675HigJul 27, 2017
    risk 0.57cvss 8.8epss 0.03

    The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array…

  • CVE-2015-3638HigJul 21, 2017
    risk 0.57cvss 8.8epss 0.02

    phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to injected scripts, or by injecting PHP into…

  • CVE-2017-9774HigJun 21, 2017
    risk 0.57cvss 8.8epss 0.02

    Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.

  • CVE-2015-2252HigJun 8, 2017
    risk 0.57cvss 8.8epss 0.02

    Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.

  • CVE-2017-9442HigJun 5, 2017
    risk 0.57cvss 8.8epss 0.02

    BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in…

  • CVE-2017-8402HigMay 31, 2017
    risk 0.57cvss 8.8epss 0.01

    PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.

  • CVE-2017-7911HigMay 6, 2017
    risk 0.57cvss 8.8epss 0.04

    A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified, which may allow remote code execution.

  • CVE-2016-4895HigApr 12, 2017
    risk 0.57cvss 8.8epss 0.02

    SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

  • CVE-2016-5072HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.02

    OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition…

  • CVE-2017-7570HigApr 7, 2017
    risk 0.57cvss 8.8epss 0.01

    PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.