Fallos del tipo CWE-78

4615 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-67438MEDIUMOliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety CheckEPSS 1.6%CVE-2023-44291HIGH Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentEPSS 1.6%CVE-2026-23699HIGHAP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exEPSS 1.6%CVE-2023-38027CRITICALSpotCam Co., Ltd. SpotCam Sense - Command InjectionEPSS 1.6%CVE-2023-22919HIGHThe post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated aEPSS 1.6%CVE-2022-48581HIGHA command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input aEPSS 1.6%CVE-2025-10619MEDIUMsequa-ai sequa-mcp OAuth Server Discovery node-oauth-client-provider.ts redirectToAuthorization os command injectionEPSS 1.6%CVE-2025-13700HIGHDreamFactory saveZipFile Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2022-40929CRITICALXXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an iEPSS 1.6%CVE-2013-10053HIGHZPanel <= 10.0.0.2 htpasswd Module Username Command ExecutionEPSS 1.6%CVE-2024-31471CRITICALThere is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code eEPSS 1.6%CVE-2024-31472CRITICALThere are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code executioEPSS 1.6%CVE-2026-48385HIGHColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 1.6%CVE-2026-59680HIGHyast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attributeEPSS 1.6%CVE-2023-33965CRITICALBrook's tproxy server is vulnerable to a drive-by command injection.EPSS 1.6%CVE-2024-53688HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 aEPSS 1.6%CVE-2026-58147CRITICALAuthorized remote code execution via password change functionality in T-Mobile 5G Box IDU routersEPSS 1.6%CVE-2024-9166CRITICALOS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite ReceiverEPSS 1.6%CVE-2022-40719HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routerEPSS 1.6%CVE-2022-37880HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%