← Back
CWE-94

6,674 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (6,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Htmltonuke
1Htmltonuke
Apr 16, 2026
Jan 19, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn param...Show more
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.Show less
1Mozilla
1Thunderbird
Apr 16, 2026
Jan 18, 2006
N/A· v4
N/A· v3
5.1 MEDIUM· v2
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending wi...Show more
GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an attachment with a filename containing a large number of spaces ending with a dangerous extension that is not displayed by Thunderbird, along with an inconsistent Content-Type header, which could be used to trick a user into downloading dangerous content by dragging or saving the attachment.Show less
1Php
1Php
Apr 16, 2026
Jan 13, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) he...Show more
Multiple HTTP response splitting vulnerabilities in PHP 5.1.1 allow remote attackers to inject arbitrary HTTP headers via a crafted Set-Cookie header, related to the (1) session extension (aka ext/session) and the (2) header function.Show less
2Apache2triad
Php
2Apache2triad
Pear
Apr 16, 2026
Jan 9, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified ve...Show more
The proxy server feature in go-pear.php in PHP PEAR 0.2.2, as used in Apache2Triad, allows remote attackers to execute arbitrary PHP code by redirecting go-pear.php to a malicious proxy server that provides a modified version of Tar.php with a malicious extractModify function.Show less
1Oaboard
1Oaboard
Apr 16, 2026
Jan 5, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provena...Show more
PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Devellion
1Cubecart
Apr 16, 2026
Jan 3, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.
1Mozilla
1Mozilla
Apr 16, 2026
Dec 31, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local p...Show more
The XMLHttpRequest object in Mozilla 1.7.8 supports the HTTP TRACE method, which allows remote attackers to obtain (1) proxy authentication passwords via a request with a "Max-Forwards: 0" header or (2) arbitrary local passwords on the web server that hosts this object.Show less
1Plogger
1Plogger
Apr 16, 2026
Dec 29, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.
1Alt N
2Mdaemon
Worldclient
Apr 16, 2026
Dec 13, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being ab...Show more
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.Show less
1Phpgreetz
1Phpgreetz
Apr 16, 2026
Nov 29, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in content.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.
1Oliver May
1Athena Php Website Administration
Apr 16, 2026
Nov 29, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.
1Q News
1Q News
Apr 16, 2026
Nov 29, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
1Desklance
1Desklance
Apr 16, 2026
Nov 26, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in support/index.php in DeskLance 2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the main parameter.
1Pollvote
1Pollvote
Apr 16, 2026
Nov 23, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter.
1First4internet Xcp Drm
1First4internet Xcp Drm
Apr 16, 2026
Nov 17, 2005
N/A· v4
N/A· v3
9.3 HIGH· v2
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such...Show more
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.Show less
1Codegrrl
5Phpcalendar
PhpcliquePhpcurrently+2 more
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local fi...Show more
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected.Show less
1Phpkit
1Phpkit
Apr 16, 2026
Nov 16, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors inv...Show more
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.Show less
2Blender
Debian
2Blender
Debian Linux
Apr 16, 2026
Oct 24, 2005
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
1Mozilla
2Firefox
Mozilla Suite
Apr 16, 2026
Sep 23, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, i...Show more
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.Show less
1Plainblack
1Webgui
Apr 16, 2026
Sep 7, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm.