CWE-894

GPTKB entity

Statements (14)
Predicate Object
gptkbp:instance_of gptkb:CEO
gptkbp:bfsLayer 6
gptkbp:bfsParent gptkb:CWE-23
gptkbp:category Code Injection
gptkbp:difficulty gptkb:High
gptkbp:example A web application that allows users to input Java Script code that is then executed on the server.
https://www.w3.org/2000/01/rdf-schema#label CWE-894
gptkbp:impact Execution of arbitrary code.
gptkbp:is_described_as The software constructs code dynamically from user input, which can lead to unintended code execution.
gptkbp:is_protected_by Validate and sanitize all user inputs.
gptkbp:name Improper Control of Generation of Code (' Code Injection')
gptkbp:related_to gptkb:CWE-74
gptkb:CWE-95
gptkb:CWE-20