375 vulnerabilities classified as CWE-74 (输出中的特殊元素转义处理不恰当(注入)). AI Chinese analysis included.
CWE-74 represents a critical input validation weakness where software constructs commands, data structures, or records using externally influenced input without properly neutralizing special elements. This flaw allows attackers to inject malicious syntax that alters the intended interpretation of the downstream component, leading to severe consequences such as unauthorized command execution, data manipulation, or system compromise. Exploitation typically occurs when user-supplied data is directly concatenated into queries or system calls without sanitization. To prevent this, developers must implement rigorous input validation, ensuring all external data is strictly checked against expected formats. Furthermore, utilizing parameterized queries, safe APIs, and context-specific encoding techniques ensures that special characters are treated as literal data rather than executable instructions, effectively neutralizing potential injection vectors before they reach the downstream processor.
$userName = $_POST["user"]; $command = 'ls -l /home/' . $userName; system($command);;rm -rf /String author = request.getParameter(AUTHOR_PARAM); ... Cookie cookie = new Cookie("author", author); cookie.setMaxAge(cookieExpiration); response.addCookie(cookie);HTTP/1.1 200 OK ... Set-Cookie: author=Jane Smith ...| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-15146 | Remote Code Execution in SyliusResourceBundle — SyliusResourceBundle | 9.6 | Critical | 2020-08-19 |
| CVE-2020-15111 | CRLF vulnerability in Fiber — fiber | 4.2 | Medium | 2020-07-20 |
| CVE-2020-11060 | Remote Code Execution in GLPI — GLPI | 7.4 | High | 2020-05-12 |
| CVE-2020-7489 | Schneider Electric EcoStruxure Machine Expert–Basic或SoMachine Basic 注入漏洞 — SoMachine Basic (all versions)EcoStruxure Machine Expert – Basic (all versions)Modicon M100 Logic Controller (all versions)Modicon M200 Logic Controller (all versions)Modicon M221 Logic Controller (all versions) | 9.8 | - | 2020-04-22 |
| CVE-2020-11002 | Remote Code Execution (RCE) vulnerability in dropwizard-validation — dropwizard | 8.0 | High | 2020-04-10 |
| CVE-2020-7475 | 多款Schneider Electric产品注入漏洞 — EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior to V3.10) | 9.8 | - | 2020-03-23 |
| CVE-2020-5245 | Remote Code Execution (RCE) vulnerability in dropwizard-validation — dropwizard-validation | 7.9 | High | 2020-02-24 |
| CVE-2020-5219 | Remote Code Execution in Angular Expressions — angular-expressions | 8.7 | High | 2020-01-24 |
| CVE-2019-11275 | CSV Injection in usage report downloaded from Pivotal Application Manager — Apps Manager | 3.5 | - | 2019-10-01 |
| CVE-2019-1939 | Cisco Webex Teams Logging Feature Command Execution Vulnerability — Cisco Webex Teams | 8.8 | - | 2019-09-05 |
| CVE-2019-3562 | Oculus Browser 跨站脚本漏洞 — Oculus Browser | 6.1 | - | 2019-04-29 |
| CVE-2019-1680 | Cisco Webex Business Suite Content Injection Vulnerability — Cisco Webex Business Suite | 4.3 | - | 2019-02-07 |
| CVE-2018-18992 | LCDS LAquis SCADA 注入漏洞 — LCDS Laquis SCADA | 9.8 | - | 2019-02-05 |
| CVE-2018-18996 | LCDS LAquis SCADA 安全漏洞 — LCDS Laquis SCADA | 9.8 | - | 2019-02-05 |
| CVE-2017-16719 | Moxa NPort 5110、5130和5150 安全漏洞 — Moxa NPort 5110, 5130, and 5150 | 7.5 | - | 2017-11-16 |
Vulnerabilities classified as CWE-74 (输出中的特殊元素转义处理不恰当(注入)) represent 375 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.