CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 42 of 143
- CVE-2017-1001004HIGHCVSS 8.8EG 8.82017-11-27
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
- CVE-2017-1002152MEDIUMCVSS 6.1EG 6.12019-01-10
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.
- CVE-2017-10835HIGHCVSS 8.8EG 8.82017-08-29
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.
- CVE-2017-10844HIGHCVSS 8.8EG 8.82017-08-29
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
- CVE-2017-10968CRITICALCVSS 9.8EG 9.82017-07-07
In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route=template request.
- CVE-2017-11167CRITICALCVSS 9.8EG 9.82017-07-12
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.
- CVE-2017-11421HIGHCVSS 7.8EG 7.82017-07-18
gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory …
- CVE-2017-11459CRITICALCVSS 9.8EG 9.82017-07-25
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.
- CVE-2017-11585CRITICALCVSS 9.8EG 9.82017-07-24
dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.
- CVE-2017-11675HIGHCVSS 8.8EG 8.82017-07-27
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invali…
- CVE-2017-11715CRITICALCVSS 9.8EG 9.82017-07-28
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving …
- CVE-2017-11760HIGHCVSS 8.8EG 8.82017-07-31
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the des…
- CVE-2017-1242MEDIUMCVSS 5.4EG 5.42018-07-06
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the…
- CVE-2017-1248MEDIUMCVSS 5.4EG 6.12018-07-06
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the…
- CVE-2017-1329MEDIUMCVSS 5.4EG 5.42018-07-06
IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the…
- CVE-2017-1336MEDIUMCVSS 4.4EG 4.42017-12-07
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
- CVE-2017-13676HIGHCVSS 7.0EG 7.02017-09-28
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the…
- CVE-2017-14077MEDIUMCVSS 6.1EG 6.12017-11-18
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.
- CVE-2017-14146HIGHCVSS 8.8EG 8.82017-09-05
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
- CVE-2017-14198HIGHCVSS 8.8EG 8.82017-11-30
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
- CVE-2017-14353HIGHCVSS 8.8EG 8.82017-10-05
A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution.
- CVE-2017-1440HIGHCVSS 8.8EG 8.82017-08-30
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to e…
- CVE-2017-1469HIGHCVSS 7.8EG 7.82017-08-14
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
- CVE-2017-14764HIGHCVSS 8.8EG 8.82017-09-27
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.
- CVE-2017-14853CRITICALCVSS 8.6EG 9.82019-06-03
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and r…
- CVE-2017-15376CRITICALCVSS 9.8EG 9.82017-10-16
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
- CVE-2017-15806HIGHCVSS 8.1EG 8.12017-11-15
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code …
- CVE-2017-15935HIGHCVSS 7.2EG 7.22017-10-27
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
- CVE-2017-16020CRITICALCVSS 9.8EG 9.82018-06-04
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
- CVE-2017-16042CRITICALCVSS 9.8EG 9.82018-06-04
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
- CVE-2017-16082CRITICALCVSS 9.8EG 9.82018-06-07
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, us…
- CVE-2017-16100CRITICALCVSS 9.8EG 9.82018-06-07
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible.
- CVE-2017-16151CRITICALCVSS 9.8EG 9.82018-06-07
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this …
- CVE-2017-16544HIGHCVSS 8.8EG 8.82017-11-20
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in…
- CVE-2017-16664HIGHCVSS 8.8EG 8.82017-11-21
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the web…
- CVE-2017-16670HIGHCVSS 7.8EG 7.82018-02-19
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
- CVE-2017-16682HIGHCVSS 7.2EG 7.22017-12-12
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control…
- CVE-2017-16783CRITICALCVSS 9.8EG 9.82017-11-10
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
- CVE-2017-16871HIGHCVSS 8.1EG 8.12017-11-17
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name pa…
- CVE-2017-16905HIGHCVSS 8.1EG 8.12018-01-05
The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in-the-middle attack.
- CVE-2017-17098CRITICALCVSS 9.8EG 9.82018-01-02
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrate…
- CVE-2017-1721MEDIUMCVSS 5.6EG 5.62018-04-26
IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810.
- CVE-2017-1753MEDIUMCVSS 5.4EG 5.42018-08-20
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Fo…
- CVE-2017-17649MEDIUMCVSS 6.1EG 6.12017-12-18
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
- CVE-2017-1789CRITICALCVSS 9.8EG 9.82018-03-22
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.
- CVE-2017-18108HIGHCVSS 7.2EG 7.22019-03-29
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.
- CVE-2017-18113HIGHCVSS 8.8EG 8.82021-08-02
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code E…
- CVE-2017-18356HIGHCVSS 8.8EG 8.82019-01-15
In the Automattic WooCommerce plugin before 3.2.4 for WordPress, an attack is possible after gaining access to the target site with a user account that has at least Shop manager privileges. The attacker then constructs a specifically craft…
- CVE-2017-18468MEDIUMCVSS 6.3EG 6.32019-08-05
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
- CVE-2017-18924HIGHCVSS 7.5EG 7.52020-10-04
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the cl…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →