Fallos del tipo CWE-78

4626 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-50919CRITICALTdarr 2.00.15 - Command InjectionEPSS 1.4%CVE-2023-0164HIGHOrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because tEPSS 1.4%CVE-2025-41270CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47900HIGHRCE on backup configuration passwordEPSS 1.4%CVE-2025-41275CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41274CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41276CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41269CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47901HIGHRCE on restore configuration passwordEPSS 1.4%CVE-2025-41272CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41277CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2022-40954MEDIUMApache Airflow Spark Provider RCE that bypass restrictions to read arbitrary filesEPSS 1.4%CVE-2025-62354CRITICALImproper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to executeEPSS 1.4%CVE-2026-48547HIGHKanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.ymlEPSS 1.4%CVE-2026-27613CRITICALCGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)EPSS 1.4%CVE-2023-27367HIGHNETGEAR RAX30 libcms_cli Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2022-50691CRITICALMiniDVBLinux 5.4 Remote Root Command Execution via commands.shEPSS 1.4%CVE-2020-24552MEDIUMAtop Technology 3G/4G LTE Cellular to Ethernet and Serial Secure Industrial Gateway - Command InjectionEPSS 1.4%CVE-2025-12489HIGHevernote-mcp-server openBrowser Command Injection Privilege Escalation VulnerabilityEPSS 1.4%CVE-2026-10273MEDIUMphp-censor Webhook Endpoint GitBuild.php os command injectionEPSS 1.4%