Fallos del tipo CWE-74

4841 resultados

Injeção de código ou comando

A aplicação constrói comandos ou queries dinâmicas concatenando entrada do usuário sem sanitização adequada, permitindo que um atacante injete código ou comandos maliciosos que serão executados com as permissões da aplicação. O risco é crítico porque o atacante passa a controlar a lógica de execução.

Ejemplo

Um login que monta a query SQL como `SELECT * FROM users WHERE email = '` + email_usuario + `'` permite que um atacante envie `admin@mail.com' OR '1'='1` e contorne autenticação. Ou um script que executa `system('ping ' + host_externo)` deixa aberto para injetar `; rm -rf /` e deletar arquivos.

Cómo mitigar

Use prepared statements (queries parametrizadas) para banco de dados, escape adequado para sistema operacional, e valide entrada contra um whitelist restrito. Nunca confie em concatenação de strings para montar comandos dinâmicos.

CVE-2026-7267MEDIUMSourceCodester Pizzafy Ecommerce System view_prod.php sql injectionEPSS 0.3%CVE-2026-7264MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php get_cart_items sql injectionEPSS 0.3%CVE-2026-6030MEDIUMitsourcecode Construction Management System del1.php sql injectionEPSS 0.3%CVE-2026-7118MEDIUMcode-projects Employee Management System cancel.php sql injectionEPSS 0.3%CVE-2026-6628MEDIUMphili67 Ecclesia CRM Query Viewer view ValidateInput sql injectionEPSS 0.3%CVE-2026-84061MEDIUMzhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injectionEPSS 0.3%CVE-2026-18766MEDIUMchetans9 core-php-admin-panel customers.php sql injectionEPSS 0.3%CVE-2026-5206MEDIUMcode-projects Simple Gym Management System Payment sql injectionEPSS 0.3%CVE-2026-5606MEDIUMPHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionEPSS 0.3%CVE-2026-7229MEDIUMcode-projects Coaching Management System POST reply.php sql injectionEPSS 0.3%CVE-2026-94492MEDIUMYonyou U8cloud OpenAPI so.saleorder.sendaudit sql injectionEPSS 0.3%CVE-2026-4485MEDIUMitsourcecode College Management System search_student.php sql injectionEPSS 0.3%CVE-2026-7114MEDIUMcode-projects Employee Management System edit.php sql injectionEPSS 0.3%CVE-2026-86171MEDIUMDefaultFuction CRM delete.php sql injectionEPSS 0.3%CVE-2026-6488MEDIUMQueryMine sms GET Request Parameter editcourse.php sql injectionEPSS 0.3%CVE-2026-7672MEDIUMyoulaitech youlai-boot Users Endpoint UserController.java getUserList sql injectionEPSS 0.3%CVE-2026-7148MEDIUMCodeAstro Online Classroom addnewfaculty sql injectionEPSS 0.3%CVE-2026-9411MEDIUMSourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injectionEPSS 0.3%CVE-2026-12776MEDIUMMontodel House-Rental-Management index.php houses sql injectionEPSS 0.3%CVE-2026-5552MEDIUMPHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionEPSS 0.3%