Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-04-16 CVE-2018-10133 Code Injection vulnerability in Pbootcms 0.9.8
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
network
low complexity
pbootcms CWE-94
critical
9.8
2018-04-13 CVE-2018-10086 Code Injection vulnerability in Cmsmadesimple CMS Made Simple
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possible to bypass certain restrictions on these "testfunction" functions.
network
low complexity
cmsmadesimple CWE-94
7.2
2018-04-12 CVE-2018-1028 Code Injection vulnerability in Microsoft products
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
network
low complexity
microsoft CWE-94
8.8
2018-04-07 CVE-2018-9848 Code Injection vulnerability in Gxlcms QY 1.0.0713
In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to change the config[upload_class] value from jpg,gif,png,jpeg to jpg,gif,png,jpeg,php and then making an Admin-Upload-Upload request.
network
low complexity
gxlcms CWE-94
critical
9.8
2018-04-07 CVE-2018-9847 Code Injection vulnerability in Gxlcms QY 1.0.0713
In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
network
low complexity
gxlcms CWE-94
critical
9.8
2018-04-04 CVE-2017-3967 Code Injection vulnerability in Mcafee Network Security Manager
Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to inject arbitrary web script or HTML via application pages inability to break out of 3rd party HTML frames.
network
low complexity
mcafee CWE-94
6.1
2018-04-02 CVE-2018-9175 Code Injection vulnerability in Dedecms 5.7
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
network
low complexity
dedecms CWE-94
critical
9.8
2018-04-02 CVE-2018-9174 Code Injection vulnerability in Dedecms 5.7
sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
network
low complexity
dedecms CWE-94
critical
9.8
2018-03-28 CVE-2018-8823 Code Injection vulnerability in multiple products
modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute arbitrary PHP code via the code parameter.
network
low complexity
responsive-mega-menu-pro-project prestashop CWE-94
critical
9.8
2018-03-26 CVE-2014-2293 Code Injection vulnerability in Zikula Application Framework
Zikula Application Framework before 1.3.7 build 11 allows remote attackers to conduct PHP object injection attacks and delete arbitrary files or execute arbitrary PHP code via crafted serialized data in the (1) authentication_method_ser or (2) authentication_info_ser parameter to index.php, or (3) zikulaMobileTheme parameter to index.php.
network
low complexity
zikula CWE-94
critical
9.8