CWE-95

Medium likelihood

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Parent: CWE-94 - Improper Control of Generation of Code ('Code Injection')

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

152 vulnerabilities with CWE-95
CVE-2013-10051 CRITICAL
InstantCMS < 1.6 - Remote PHP Code Execution via Search View Handler
CVSS 9.8
CVE-2011-10033 CRITICAL
WordPress Plugin <=1.4.2 - Code Injection
Details
Vulnerabilities 152
Exploit Likelihood Medium