Cwe 94

🧬 CWE Related 84
slug: cwe-94

Explanation

CWE-94は「攻撃者が送ったデータが、プログラムコードとして解釈・実行されてしまう」欠陥です。 Pythonの `eval()`・PHPの `eval()`/`include()` にユーザー入力を渡すような実装が典型例です。 リモートコード実行 (RCE) の直接的な原因となるため、最も重大なクラスの脆弱性です。
📌 Example
Log4Shell (CVE-2021-44228) はLog4jのJNDI Lookupを悪用したコードインジェクションで、世界中のJavaサーバーが数日でハッキングされた。

🔖 Related tags

🛡 Vulnerabilities tagged with this 1,128

ID Title
CVE-2023-46010 Code Injection in seacms (CVE-2023-46010)
CVE-2023-41450 Code Injection in phpkobo (CVE-2023-41450)
CVE-2018-14667 KEV [KEV] Code Injection in Red hat red-hat (CVE-2018-14667)
CVE-2023-43234 Code Injection in dedebiz (CVE-2023-43234)
CVE-2023-33246 KEV [KEV] Code Injection in Apache rocketmq (CVE-2023-33246)
CVE-2023-33469 Code Injection in kramerav (CVE-2023-33469)
CVE-2023-36095 Code Injection in langchain (CVE-2023-36095)
CVE-2023-36255 Code Injection in eramba (CVE-2023-36255)
CVE-2023-34842 Code Injection in dedecms (CVE-2023-34842)
CVE-2023-3519 KEV [KEV] Code Injection in Citrix netscaler-adc-and-netscaler-gateway (CVE-2023-3519)
CVE-2022-47879 Code Injection in jedox (CVE-2022-47879)
CVE-2023-25717 KEV [KEV] Code Injection in Ruckus wireless ruckus-wireless (CVE-2023-25717)
CVE-2023-30404 Code Injection in aigital (CVE-2023-30404)
CVE-2023-29492 KEV [KEV] Code Injection in Novi survey novi-survey (CVE-2023-29492)
CVE-2013-3163 KEV [KEV] Code Injection in Microsoft internet-explorer (CVE-2013-3163)
CVE-2017-7494 KEV [KEV] Code Injection in samba (CVE-2017-7494)
CVE-2023-25261 Code Injection in stimulsoft (CVE-2023-25261)
CVE-2021-39144 KEV [KEV] Vulnerability in com.thoughtworks.xstream:xstream (CVE-2021-39144)
CVE-2022-45553 Code Injection in zbt (CVE-2022-45553)
CVE-2022-41223 KEV [KEV] Code Injection in Mitel mivoice-connect (CVE-2022-41223)
CVE-2023-21553 Azure DevOps Server Remote Code Execution Vulnerability
CVE-2022-44702 Windows Terminal Remote Code Execution Vulnerability
CVE-2022-44087 Code Injection in ecisp (CVE-2022-44087)
CVE-2022-44088 Code Injection in ecisp (CVE-2022-44088)
CVE-2022-44089 Code Injection in ecisp (CVE-2022-44089)
CVE-2022-41061 Microsoft Word Remote Code Execution Vulnerability
CVE-2022-3236 KEV [KEV] Code Injection in Sophos firewall (CVE-2022-3236)
CVE-2022-37053 TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
CVE-2022-22963 KEV [KEV] Code Injection in Vmware tanzu vmware-tanzu (CVE-2022-22963)
CVE-2022-36262 Code Injection in taogogo (CVE-2022-36262)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →