Fallos del tipo CWE-78

4616 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-37882HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%CVE-2022-3183CRITICALDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provideEPSS 1.6%CVE-2024-53899HIGHvirtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not EPSS 1.6%CVE-2024-36360CRITICALOS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote EPSS 1.6%CVE-2020-15121HIGHCommand injection in Radare2EPSS 1.6%CVE-2026-29058CRITICALAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.phpEPSS 1.6%CVE-2023-23692HIGH Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially EPSS 1.6%CVE-2025-32107HIGHOS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vEPSS 1.6%CVE-2022-37924HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.6%CVE-2026-72573HIGH4xmen pm2panel - Authenticated OS Command Injection via id Query ParameterEPSS 1.6%CVE-2018-25122HIGHNagios XI < 5.4.13 Component Download Page RCEEPSS 1.6%CVE-2024-58314HIGHAtcom 2.7.x.x Authenticated Command Injection via Web Configuration CGIEPSS 1.6%CVE-2022-48583HIGHA command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 1.6%CVE-2022-48584HIGHA command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐contEPSS 1.6%CVE-2022-48582HIGHA command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlleEPSS 1.6%CVE-2026-50206HIGHVPN Command Injection VulnerabilityEPSS 1.6%CVE-2026-45662HIGHDokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)EPSS 1.6%CVE-2026-25836MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5EPSS 1.6%CVE-2024-1367HIGHCommand Injection Vulnerability in Tenable Security CenterEPSS 1.6%CVE-2024-45882HIGHDrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainEPSS 1.6%