CWE-116
High likelihoodImproper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
446 vulnerabilities with CWE-116
CVE-2018-20586
MEDIUM
Bitcoin Core - Arbitrary Data Injection into Debug Log via RPC Call
CVSS 5.3
CVE-2018-16386
HIGH
SWIFT Alliance Web Platform 7.1.23 - Log Injection
CVSS 7.5
CVE-2018-18838
HIGH
Netdata 1.10.0 - Log Injection via URL Parameter
CVSS 7.5
CVE-2018-8920
HIGH
Synology DiskStation Manager < 6.1.6-15266 - Arbitrary Content Injection via Log Exporter CSV Export
CVSS 7.2
CVE-2018-8609
HIGH
Microsoft Dynamics 365 8.0-8.2.3.0003 - Remote Code Execution via Improper Web Request Sanitization
CVSS 8.8
CVE-2018-15494
CRITICAL
Dojo Toolkit <1.14 - Code Injection
CVSS 9.8
CVE-2018-9246
CRITICAL
PGObject::Util::DBAdmin <0.120.0 - Code Injection
CVSS 9.8
CVE-2018-2389
MEDIUM
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - Log File Injection
CVSS 5.7
CVE-2018-1048
HIGH
JBoss EAP 7.1.0.GA - Path Traversal and Information Disclosure via AJP Connector
CVSS 7.5
CVE-2017-18892
MEDIUM
Mattermost Server <4.2.0-4.0.5 - XSS
CVSS 6.1
CVE-2017-12340
MEDIUM
Cisco NX-OS - Authenticated Bash Shell Access via Python Scripting Sandbox Escape
CVSS 4.2
CVE-2017-12064
HIGH
OpenEMR 5.0.0 and prior - Improper Encoding or Escaping of Output in csv_log_html Function
CVSS 7.5
CVE-2017-8303
CRITICAL
Accellion File Transfer Appliance < 9_12_180 - Remote Code Execution via seos/1000/find.api Method Parameter
CVSS 9.8
CVE-2016-2568
HIGH
polkit - Local Privilege Escalation via TIOCSTI ioctl Call
CVSS 7.8
CVE-2016-3063
HIGH
NetApp OnCommand System Manager <8.3.2 - RCE
CVSS 7.5
CVE-2015-10040
MEDIUM
gitlearn < 2015-06-09 - Injection in Escape Sequence Handler
CVSS 5.4
CVE-2015-10011
MEDIUM
OpenDNS OpenResolve - Info Disclosure
CVSS 4.6
CVE-2014-9938
HIGH
Git < 1.9.3 - Remote Code Execution via Unsanitized Branch Name in PS1 Variable
CVSS 8.8
CVE-2013-2011
HIGH
WordPress W3 Super Cache <1.3.2 - RCE
CVSS 8.8
CVE-2013-4547
nginx 0.8.41-1.4.3 and 1.5.x < 1.5.7 - URI Restriction Bypass via Unescaped Space Character
CVE-2009-4267
MEDIUM
Apache jUDDI 3.0.0 - Authenticated Log Spoofing via Console numRows Parameter
CVSS 6.5
Details
Vulnerabilities
446
Exploit Likelihood
High