CWE-116

High likelihood

Improper Encoding or Escaping of Output

Parent: CWE-707 - Improper Neutralization

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

482 vulnerabilities with CWE-116
CVE-2016-3063 HIGH
NetApp OnCommand System Manager <8.3.2 - RCE
CVSS 7.5
CVE-2015-10040 MEDIUM
gitlearn < 2015-06-09 - Injection in Escape Sequence Handler
CVSS 5.4
CVE-2015-10011 MEDIUM
OpenDNS OpenResolve - Info Disclosure
CVSS 4.6
CVE-2014-9938 HIGH
Git < 1.9.3 - Remote Code Execution via Unsanitized Branch Name in PS1 Variable
CVSS 8.8
CVE-2013-2011 HIGH
WordPress W3 Super Cache <1.3.2 - RCE
CVSS 8.8
CVE-2013-4547
nginx 0.8.41-1.4.3 and 1.5.x < 1.5.7 - URI Restriction Bypass via Unescaped Space Character
CVE-2009-4267 MEDIUM
Apache jUDDI 3.0.0 - Authenticated Log Spoofing via Console numRows Parameter
CVSS 6.5
Details
Vulnerabilities 482
Exploit Likelihood High