Rapid7 Vulnerability & Exploit Database

Code Injection

Back to Search

Code Injection

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
06/08/2006
Created
07/25/2018
Added
03/23/2012
Modified
06/20/2013

Description

Code injection is the general name for many types of attacks that involve introducing malicious code into applications. For example, attackers may send code as values of form fields or add argument values in uniform resource identifiers (URIs). These attacks exploit lack of accurate input/output data validation.

Code injection vulnerabilities belong to the A1 category in the OWASP 2010 Top Ten Security Risks.

Solution(s)

  • spider-code-injection

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;