CWE-97

Improper Neutralization of Server-Side Includes (SSI) Within a Web Page
AI Translation Available

The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.

Status
draft
Abstraction
variant
Web Based Web Server

Common Consequences

confidentiality integrity availability
Impacts
execute unauthorized code or commands

Potential Mitigations