Fallos del tipo CWE-78

4622 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-37878HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.5%CVE-2026-16488LOWQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injectionEPSS 1.5%CVE-2023-3741—An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on theEPSS 1.5%CVE-2026-59681HIGHyast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD joinEPSS 1.5%CVE-2026-49481CRITICALUpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmdEPSS 1.5%CVE-2025-2733MEDIUMmannaandpoem OpenManus Prompt python_execute.py os command injectionEPSS 1.5%CVE-2024-43656CRITICALA backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.EPSS 1.5%CVE-2023-28983HIGHJunos OS Evolved: Shell Injection vulnerability in the gNOI serverEPSS 1.5%CVE-2023-35961HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35962HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35959HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35963HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2026-9862CRITICALCore Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityEPSS 1.5%CVE-2023-35964HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35960HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2021-31799HIGHIn RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a EPSS 1.5%CVE-2026-0795HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-21191HIGHVersions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checEPSS 1.5%CVE-2022-40740HIGHRealtek GPON router - Command InjectionEPSS 1.5%CVE-2026-26280HIGHSysteminformation has a Command Injection via unsanitized interface parameter in wifi.js retry pathEPSS 1.5%