The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as record delimiters when they are sent to a downstream
component.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as line delimiters when they are sent to a downstream
component.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as section delimiters when they are sent to a downstream
component.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as expression or command delimiters when they are sent to a
downstream component.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as input terminators when they are sent to a downstream
component.
The application does not properly handle when a leading
character or sequence ("leader") is missing or malformed, or if multiple leaders
are used when only one should be allowed.
Quotes injected into an application can be used to compromise a
system. As data are parsed, an injected/absent/duplicate/malformed use of quotes
may cause the process to take unexpected actions.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as escape, meta, or control character sequences when they are sent
to a downstream component.
The software receives input from an upstream component, but it
does not neutralize or incorrectly neutralizes special elements that could be
interpreted as comment delimiters when they are sent to a downstream
component.