Fallos del tipo CWE-77

2816 resultados

Injeção de comando via entrada não sanitizada

O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.

Ejemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.

Cómo mitigar

Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.

CVE-2022-20925MEDIUMA vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remoteEPSS 0.9%CVE-2026-21257HIGHGitHub Copilot and Visual Studio Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2025-44844MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileNameEPSS 0.9%CVE-2025-44841MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2025-44840MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2025-44860MEDIUMTOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port paramEPSS 0.9%CVE-2025-44848MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url paramEPSS 0.9%CVE-2025-44842MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port paraEPSS 0.9%CVE-2025-44845MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTEPSS 0.9%CVE-2025-44863MEDIUMTOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameEPSS 0.9%CVE-2025-44839MEDIUMTOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function EPSS 0.9%CVE-2021-31356HIGHJunos OS Evolved: Multiple shell-injection vulnerabilities in EVO UI wrapper scriptsEPSS 0.9%CVE-2022-36769HIGHIBM Cloud Pak for Data file uploadEPSS 0.9%CVE-2026-48561CRITICALMicrosoft Edge Copilot Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-49179HIGHWindows Active Directory Domain Services Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-45800CRITICALTOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/gEPSS 0.9%CVE-2018-0217—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.9%CVE-2023-38690MEDIUMmatrix-appservice-irc IRC command injection via admin commands containing newlines EPSS 0.9%CVE-2026-35428CRITICALAzure Cloud Shell Spoofing VulnerabilityEPSS 0.9%CVE-2026-84190HIGHLibreNMS before 26.5.0 Remote Code Execution via AboutControllerEPSS 0.9%