Fallos del tipo CWE-78

4626 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-10273MEDIUMphp-censor Webhook Endpoint GitBuild.php os command injectionEPSS 1.4%CVE-2026-27938HIGHWPGraphQL Repo Vulnerable to Command Injection via Unsanitized GitHub Actions Expression in Release WorkflowEPSS 1.4%CVE-2024-11062HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11064HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11063HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11065HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2022-32752HIGHIBM Security Directory Suite VA command executionEPSS 1.4%CVE-2020-8130—There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe cEPSS 1.4%CVE-2022-45899MEDIUMNokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metaEPSS 1.4%CVE-2009-20011CRITICALContentKeeper Web Appliance < 125.10 RCE via mimencodeEPSS 1.4%CVE-2022-48069HIGHTotolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.EPSS 1.4%CVE-2022-41395HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in EPSS 1.4%CVE-2022-41396HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIEPSS 1.4%CVE-2026-22221HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1EPSS 1.4%CVE-2024-57025MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiSEPSS 1.4%CVE-2024-33434CRITICALAn issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows aEPSS 1.4%CVE-2024-57023MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiSEPSS 1.4%CVE-2025-11148CRITICALAll versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted withEPSS 1.4%CVE-2026-11526CRITICALGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleEPSS 1.4%CVE-2025-39240HIGHSome Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. AttackerEPSS 1.4%