Fallos del tipo CWE-78

4606 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-11900CRITICALHGiga|iSherlock - OS Command InjectionEPSS 1.8%CVE-2023-3267CRITICALWhen adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passeEPSS 1.8%CVE-2023-37927HIGHThe improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwareEPSS 1.8%CVE-2026-4408CRITICALSamba: remote code execution in samrEPSS 1.8%CVE-2024-2662HIGHUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command InjectionEPSS 1.7%CVE-2019-5071HIGHAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart DualEPSS 1.7%CVE-2022-41131HIGHApache Airflow Hive Provider vulnerability (command injection via hive_cli connection)EPSS 1.7%CVE-2025-34132CRITICALLILIN DVR Command Injection via NTPUpdate in dvr_boxEPSS 1.7%CVE-2024-52034CRITICALmySCADA myPRO OS Command InjectionEPSS 1.7%CVE-2020-8007CRITICALThe pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via thEPSS 1.7%CVE-2021-32524CRITICALQSAN Storage Manager - Command Injection-3EPSS 1.7%CVE-2025-34239HIGHAdvantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()EPSS 1.7%CVE-2023-39295HIGHQuMagieEPSS 1.7%CVE-2024-57011HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScEPSS 1.7%CVE-2025-34042CRITICALBeward N100 IP Camera Remote Command ExecutionEPSS 1.7%CVE-2026-87911CRITICALRead-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-serverEPSS 1.7%CVE-2024-48826HIGHTenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2024-48825HIGHTenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2022-4643MEDIUMdocconv pdf_ocr.go ConvertPDFImages os command injectionEPSS 1.7%CVE-2023-48662HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%