CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,843 vulnerabilities with CWE-74
CVE-2017-18604 HIGH
sitebuilder-dynamic-components < 1.0 - PHP Object Injection via AJAX Request
CVSS 7.5
CVE-2017-18583 CRITICAL
Post Pay Counter < 2.731 - PHP Object Injection
CVSS 9.8
CVE-2017-18437 MEDIUM
cPanel < 56.0.49 - Authenticated Remote Code Execution via Webmail Forwarder
CVSS 4.4
CVE-2017-18389 MEDIUM
cPanel < 64.0.42 - String Format Injection in dovecot-xaps-plugin
CVSS 6.3
CVE-2017-18387 HIGH
cPanel 61.9999.55-62.0.35 - Remote Code Execution via Maketext Injection in Reseller Style Upload
CVSS 7.2
CVE-2017-18386 HIGH
cPanel 61.9999.55-61.9999.9999 - Remote Code Execution via Maketext Injection in PostgresAdmin
CVSS 7.2
CVE-2017-1202 MEDIUM
IBM BigFix Compliance 1.7-1.9.91 - HTML Injection
CVSS 5.4
CVE-2017-1115 MEDIUM
IBM Campaign 9.1, 9.1.2, and 10 - HTML Injection
CVSS 5.4
CVE-2017-7848 MEDIUM
Thunderbird < 52.5.2 - Email Header Injection via RSS Feed
CVSS 5.3
CVE-2017-7846 HIGH
Redhat Enterprise Linux Desktop < 52.5.2 - Injection
CVSS 8.8
CVE-2017-7788 CRITICAL
Firefox < 55.0 - Content Security Policy Bypass via Sandboxed Iframe with srcdoc
CVSS 9.8
CVE-2017-16043 MEDIUM
shout 0.44.0-0.49.3 - Cross-Site Scripting via /topic Command
CVSS 6.1
CVE-2017-6015 HIGH
Rockwell Automation FactoryTalk Activation < 4.00.02 - Unquoted Search Path or Element
CVSS 7.8
CVE-2017-18266 HIGH
xdg-utils < 1.1.3 - Argument Injection via BROWSER Environment Variable
CVSS 8.8
CVE-2017-0372 CRITICAL
MediaWiki < 1.23.16, 1.27.3, 1.28.2 - Parameter Injection in SyntaxHighlight Extension
CVSS 9.8
CVE-2017-4028 MEDIUM
McAfee Anti-Virus Plus - Authenticated Code Injection via Registry Manipulation
CVSS 5.0
CVE-2017-10963 MEDIUM
Samsung Knox SDS IAM and EMM 16.11 - Unauthenticated Application Installation via Man-in-the-Middle Update Injection
CVSS 5.9
CVE-2017-5799 HIGH
HPE OpenCall Media Platform < 3.4.2 - Remote Code Execution
CVSS 8.8
CVE-2017-14523 HIGH
WonderCMS 2.3.1 - HTTP Host Header Injection
CVSS 7.5
CVE-2017-18049 MEDIUM
SilverStripe < 3.5.6, 3.6.x < 3.6.3, 4.x < 4.0.1 - CSV Injection via User Profile Fields
CVSS 5.5
CVE-2017-14094 CRITICAL
Trend Micro Smart Protection Server <3.2 - Command Injection
CVSS 9.8
CVE-2017-15714 CRITICAL
Apache OFBiz 16.11.01-16.11.03 - Cross-Site Scripting via BIRT Plugin URL Parameter
CVSS 9.8
CVE-2017-1000493 CRITICAL
Rocket.Chat Server <0.59 - Info Disclosure
CVSS 9.8
CVE-2017-1000454 HIGH
CMS Made Simple <2.2.1 - Code Injection
CVSS 7.8
CVE-2017-1000453 CRITICAL
CMS Made Simple <2.1.6-2.2 - Code Injection
CVSS 9.8
Details
Vulnerabilities 4,843
Exploit Likelihood High