Fallos del tipo CWE-78

4608 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2024-23060CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg fuEPSS 1.7%CVE-2025-5952MEDIUMZend.To NSSDropoff.php exec os command injectionEPSS 1.7%CVE-2025-6559CRITICALSapido Wireless Router - OS Command InjectionEPSS 1.7%CVE-2023-3767CRITICALOS command injection on EasyPHP Webserver EPSS 1.7%CVE-2023-35762CRITICALOS Command Injection in INEA ME RTUEPSS 1.7%CVE-2026-40499HIGHradare2 < 6.1.4 Command Injection via PDB Parser print_gvars()EPSS 1.7%CVE-2026-68861HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 1.7%CVE-2025-34099CRITICALVICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth PasswordEPSS 1.7%CVE-2022-39951HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.EPSS 1.7%CVE-2026-49261CRITICALMariaDB server has unsafe parameter handling in `wsrep_notify_cmd`EPSS 1.7%CVE-2024-43651CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.7%CVE-2026-40079HIGHCacti: Command Injection via escape_command() no-op in RRDtool executionEPSS 1.7%CVE-2024-8807CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-24899HIGHCommand injection in aops-zeusEPSS 1.7%CVE-2026-45391HIGHLocal privilege escalation in Cribl Edge for LinuxEPSS 1.7%CVE-2024-8806CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0780HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0779HIGHALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0781HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-31977HIGHAdtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters EPSS 1.7%