icon

We found results for “

WS-2016-7085

Good to know:

icon
icon

Date: October 17, 2016

All versions of the package System.Linq.Dynamic are vulnerable to Code Injection, due to an issue with restricting execution methods.

Language: C#

Severity Score

Severity Score

Weakness Type (CWE)

Code

CWE-17

Improper Control of Generation of Code ('Code Injection')

CWE-94

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-74

Top Fix

icon

Upgrade Version

Upgrade to version WPFtoolkitFramework - 1.0.7.4;emFramework - no_fix;MH.Infrastucture.Data - 1.0.1;MH.Application - 1.0.1;C21.Core.App.Service - no_fix;XComponent.Community - no_fix;QCommon.UI.DevExpress - 1.0.6246.38425;Morestachio.NetFramework - 2.3.3;MH.DomainLayer.Core - 1.0.1;Servicefull.Spy.Community - no_fix;Cireson.Platform.SDK - no_fix;Net.Appclusive.PS.Client - no_fix;WgCommonLib - no_fix;DecommServiceClientNuget - no_fix;XComponent.Spy.Community - no_fix;MakeSensWebAccessAPI - no_fix;Cireson.Platform.Core.Testing - no_fix;XComponent.Studio.Community - no_fix;Servicefull.Studio.Community - no_fix;Cireson.AssetManagement.Connectors.ConfigMgr.Core - 0.1.0-integration0001;CROSSBRIDGE.DxServices - 1.0.1;C21.Core.App.Domain - no_fix;help - no_fix;System.Linq.Dynamic - no_fix;GlassDesigner.Migrator - no_fix;pacage - no_fix;Cireson.Platform.Extension.OpenIdADAL - no_fix;Cireson.AssetManagement.Core - 0.1.0-rc0126;Cevi.Adhoc - 1.0.0.1;Defontana.Sesiones - 4.5.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us