CWE-829— Inclusion of Functionality from Untrusted Control Sphere
147 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 1 of 3
- CVE-2012-4919CRITICALCVSS 9.8EG 9.82020-01-22
Gallery Plugin1.4 for WordPress has a Remote File Include Vulnerability
- CVE-2013-1945LOWCVSS 3.3EG 3.32019-10-31
ruby193 uses an insecure LD_LIBRARY_PATH setting.
- CVE-2013-3321HIGHCVSS 7.5EG 7.52020-01-29
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
- CVE-2013-4582MEDIUMCVSS 6.5EG 6.52020-01-28
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 a…
- CVE-2017-14095HIGHCVSS 8.12018-01-19
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.
- CVE-2017-5397CRITICALCVSS 9.82018-06-11
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the fil…
- CVE-2018-1000502HIGHCVSS 7.22018-06-26
MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance -> Task Manager -> Add New Task) that can result in Allows Local File Inclusion on modern PHP versions and Remote File Inclusion on ancient PHP v…
- CVE-2018-11040HIGHCVSS 7.52018-06-25
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for RES…
- CVE-2018-1122HIGHCVSS 7.32018-05-23
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-controlled directory, the attacker could achieve privilege escalation by exploiting one of several vuln…
- CVE-2018-12120HIGHCVSS 8.12018-11-28
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow r…
- CVE-2018-15486CRITICALCVSS 9.12018-09-07
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka K…
- CVE-2018-17246CRITICALCVSS 9.82018-12-20
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibl…
- CVE-2018-18387HIGHCVSS 8.82018-10-29
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
- CVE-2018-7422HIGHCVSS 7.52018-03-19
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to retrieve arbitrary files via the ajax_path parameter to editor/extensions/pagebuilder/includes/ajax_shortcode_pattern.php…
- CVE-2018-8351MEDIUMCVSS 6.52018-08-15
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Inte…
- CVE-2019-10240HIGHCVSS 8.12019-04-03
Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build ar…
- CVE-2019-10248HIGHCVSS 8.12019-04-22
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts…
- CVE-2019-10249HIGHCVSS 8.12019-05-06
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
- CVE-2019-10666HIGHCVSS 8.1EG 8.12019-09-09
An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attac…
- CVE-2019-11590HIGHCVSS 8.82019-04-29
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['actio…
- CVE-2019-11591HIGHCVSS 8.82019-04-29
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST[…
- CVE-2019-11742MEDIUMCVSS 6.5EG 6.52019-09-27
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an error in how same-origin policy is applied to cached image content. The resulting s…
- CVE-2019-11770HIGHCVSS 8.12019-06-14
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build …
- CVE-2019-13589CRITICALCVSS 9.8EG 9.82019-07-14
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
- CVE-2019-15839HIGHCVSS 7.5EG 7.52019-08-30
The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
- CVE-2019-16951MEDIUMCVSS 5.3EG 5.32019-11-13
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST request is sent, it retrieves an attack…
- CVE-2019-17014HIGHCVSS 7.4EG 7.42020-01-08
If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71.
- CVE-2019-4263MEDIUMCVSS 4.3EG 4.32019-07-11
IBM Content Navigator 3.0CD is vulnerable to local file inclusion, allowing an attacker to access a configuration file in the ICN server. IBM X-Force ID: 160015.
- CVE-2019-5479HIGHCVSS 7.5EG 7.52019-09-03
An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production code (JavaScript file).
- CVE-2019-8154HIGHCVSS 8.8EG 8.82019-11-06
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file…
- CVE-2019-9829HIGHCVSS 8.82019-03-15
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohi…
- CVE-2020-10865HIGHCVSS 7.5EG 7.52020-04-01
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to make arbitrary changes to the Components section of the Stats.ini file via RPC fr…
- CVE-2020-13175HIGHCVSS 7.5EG 7.52020-08-11
The Management Interface of the Teradici Cloud Access Connector and Cloud Access Connector Legacy for releases prior to April 20, 2020 (v15 and earlier for Cloud Access Connector) contains a local file inclusion vulnerability which allows …
- CVE-2020-13651HIGHCVSS 7.8EG 7.82020-06-15
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java applic…
- CVE-2020-13977MEDIUMCVSS 4.9EG 4.92020-06-09
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and …
- CVE-2020-16152CRITICALCVSS 9.8EG 9.82021-11-14
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log fil…
- CVE-2020-22474MEDIUMCVSS 6.5EG 6.52021-02-22
In webERP 4.15, the ManualContents.php file allows users to specify the "Language" parameter, which can lead to local file inclusion.
- CVE-2020-24985HIGHCVSS 8.1EG 8.12021-03-15
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payload…
- CVE-2020-25414CRITICALCVSS 9.8EG 9.82021-06-17
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
- CVE-2020-25788HIGHCVSS 8.1EG 8.12020-09-19
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
- CVE-2020-29072MEDIUMCVSS 6.1EG 6.12020-11-25
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/…
- CVE-2020-3794CRITICALCVSS 9.8EG 9.82020-03-25
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
- CVE-2020-4561CRITICALCVSS 10.0EG 10.02021-06-01
IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control requests in unauthenticated sessions. This allows a remote attacker who can access a valid CA endpoint to read and write files to the Cognos Analytics system. IBM …
- CVE-2020-5295MEDIUMCVSS 4.8EG 4.82020-06-03
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to read local files of an October CMS server. The vulnerability is only exploitable by an authenticated b…
- CVE-2020-8128CRITICALCVSS 9.8EG 9.82020-02-14
An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.
- CVE-2021-20187HIGHCVSS 7.2EG 7.22021-01-28
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
- CVE-2021-20443HIGHCVSS 8.8EG 8.82021-02-18
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.
- CVE-2021-20843MEDIUMCVSS 5.4EG 5.42021-11-24
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to …
- CVE-2021-21804CRITICALCVSS 9.8EG 9.82021-07-16
A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafte…
- CVE-2021-26271MEDIUMCVSS 6.5EG 6.52021-01-26
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →