Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2017-08-17 CVE-2017-6782 Code Injection vulnerability in Cisco Prime Infrastructure 3.2(0.0)
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application.
network
low complexity
cisco CWE-94
5.4
2017-08-17 CVE-2011-0469 Code Injection vulnerability in Suse Opensuse
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
network
low complexity
suse CWE-94
critical
9.8
2017-08-14 CVE-2017-1469 Code Injection vulnerability in IBM Infosphere Information Server 11.3/11.5/9.1
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories.
local
low complexity
ibm CWE-94
7.8
2017-08-10 CVE-2017-3753 Code Injection vulnerability in Lenovo products
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc.
low complexity
lenovo CWE-94
6.8
2017-07-31 CVE-2017-11760 Code Injection vulnerability in Projeqtor
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area.
network
low complexity
projeqtor CWE-94
8.8
2017-07-28 CVE-2017-11715 Code Injection vulnerability in Metinfo Project Metinfo
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php.
network
low complexity
metinfo-project CWE-94
critical
9.8
2017-07-27 CVE-2017-11675 Code Injection vulnerability in Zen-Cart ZEN Cart 1.5.5E
The traverseStrictSanitize function in admin_dir/includes/classes/AdminRequestSanitizer.php in ZenCart 1.5.5e mishandles key strings, which allows remote authenticated users to execute arbitrary PHP code by placing that code into an invalid array index of the admin_name array parameter to admin_dir/login.php, if there is an export of an error-log entry for that invalid array index.
network
low complexity
zen-cart CWE-94
8.8
2017-07-25 CVE-2017-11459 Code Injection vulnerability in SAP Trex 7.10
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.
network
low complexity
sap CWE-94
critical
9.8
2017-07-24 CVE-2017-11585 Code Injection vulnerability in Finecms 5.0.9
dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.
network
low complexity
finecms CWE-94
critical
9.8
2017-07-21 CVE-2015-3640 Code Injection vulnerability in PHPmybackuppro
phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.
network
high complexity
phpmybackuppro CWE-94
7.5