Vulnerabilities > Inclusion of Functionality from Untrusted Control Sphere

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-1376 Inclusion of Functionality from Untrusted Control Sphere vulnerability in IBM Operations Analytics Predictive Insights
A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges.
network
low complexity
ibm CWE-829
critical
9.8
2017-03-16 CVE-2017-6381 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Drupal
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution.
network
high complexity
drupal CWE-829
8.1
2010-08-19 CVE-2010-2076 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache CXF
Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.
network
low complexity
apache CWE-829
critical
9.8
2004-11-23 CVE-2004-0285 Inclusion of Functionality from Untrusted Control Sphere vulnerability in multiple products
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
9.8
2004-01-20 CVE-2004-0030 Inclusion of Functionality from Untrusted Control Sphere vulnerability in PHPgedview 2.61
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitrary PHP code by modifying the PGV_BASE_DIRECTORY parameter to reference a URL on a remote web server that contains the code.
network
low complexity
phpgedview CWE-829
critical
9.8