← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Phpmywind
1Phpmywind
Nov 21, 2024
Sep 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field.
1Phpmywind
1Phpmywind
Nov 21, 2024
Sep 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
1Phpmywind
1Phpmywind
Nov 21, 2024
Sep 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
1Phpmywind
1Phpmywind
Nov 21, 2024
Sep 17, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
1Chshcms
1Cscms
Nov 21, 2024
Sep 17, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
1Ucms Project
1Ucms
Nov 21, 2024
Sep 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
1Bigtreecms
1Bigtree Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
1Elefantcms
1Elefant
Nov 21, 2024
Sep 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php conten...Show more
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.Show less
1Intel
1Sa 00086 Detection Tool
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary code via local access.
1Monstra
1Monstra
Nov 21, 2024
Sep 10, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP...Show more
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to execute arbitrary PHP code by placing this code after a <?php substring.Show less
1Hoosk
1Hoosk
Nov 21, 2024
Sep 10, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Hoosk v1.7.0 allows PHP code execution via a SiteUrl that is provided during installation and mishandled in config.php.
1Nibbleblog
1Nibbleblog
Nov 21, 2024
Sep 6, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpin...Show more
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").Show less
1Hibara
1Attachecase
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
1Hibara
1Attachecase
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
1Seacms
1Seacms
Nov 21, 2024
Sep 2, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
1Microfocus
8Data Center Automation
Hybrid Cloud ManagementNetwork Operations Management+5 more
Jun 17, 2026
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Cont...Show more
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05, Service Virtualization (SV) with floating licenses using Any version using APLS older than 10.7, Unified Functional Testing (UFT) with floating licenses using Any version using APLS older than 10.7, Network Virtualization (NV) with floating licenses using Any version using APLS older than 10.7 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.Show less
1Microfocus
5Data Center Automation
Hybrid Cloud ManagementNetwork Operations Management+2 more
Jun 17, 2026
Aug 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Cont...Show more
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02, 2018.05 and Network Operations Management (NOM) Suite CDF 2017.11, 2018.02, 2018.05 will allow Remote Code Execution.Show less
4Apache
CanonicalDebian+1 more
7Debian Linux
Enterprise LinuxEnterprise Linux Desktop+4 more
Nov 21, 2024
Aug 26, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code fo...Show more
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes.Show less
1Couchbase
1Couchbase Server
Nov 21, 2024
Aug 24, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send arbitrary Erlang code to the 'diag/eval'...Show more
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send arbitrary Erlang code to the 'diag/eval' endpoint of the API and the code would subsequently be executed in the underlying operating system with privileges of the user which was used to start Couchbase. Affects Version: 4.0.0, 4.1.2, 4.5.1, 5.0.0, 4.6.5, 5.0.1, 5.1.1, 5.5.0, 5.5.1. Fix Version: 6.0.0, 5.5.2Show less
1Ibm
6Rational Doors Next Generation
Rational Engineering Lifecycle ManagerRational Quality Manager+3 more
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hos...Show more
Multiple IBM Rational products are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 135655.Show less