VYPR

CWE-96

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

BaseDraft

Description

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-35 · CAPEC-73 · CAPEC-77 · CAPEC-81 · CAPEC-85

CVEs mapped to this weakness (25)

page 2 of 2
  • CVE-2022-3960MedApr 3, 2023
    risk 0.41cvss 6.3epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a system administrator to disable scripting capabilities of the Community Dashboard Editor (CDE) plugin. 

  • CVE-2024-13263MedJan 9, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.

  • CVE-2024-37900MedJul 31, 2024
    risk 0.36cvss 6.4epss 0.16

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into…

  • CVE-2023-0566MedJan 29, 2023
    risk 0.33cvss 6.2epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in froxlor/froxlor prior to 2.0.10.

  • CVE-2024-32487HigApr 13, 2024
    risk 0.00cvss 8.6epss 0.01

    less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation…