Fallos del tipo CWE-78

4627 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-29048HIGHA component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runEPSS 1.3%CVE-2025-47212MEDIUMQTS, QuTS heroEPSS 1.3%CVE-2026-48997HIGHe107: Command Injection via shell expansion in ImageMagick resize destination pathEPSS 1.3%CVE-2024-45885HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2022-25890HIGHAll versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization. EPSS 1.3%CVE-2024-45891HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2022-24431HIGHCommand InjectionEPSS 1.3%CVE-2026-0596CRITICALCommand Injection in mlflow/mlflowEPSS 1.3%CVE-2026-40029HIGHparseusbs < 1.9 Command Injection via Crafted LNK FilenameEPSS 1.3%CVE-2020-12149MEDIUMOS Command Injection - Management File UploadEPSS 1.3%CVE-2024-44678HIGHGigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commaEPSS 1.3%CVE-2023-42788HIGHAn improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiEPSS 1.3%CVE-2026-22223HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1EPSS 1.3%CVE-2023-33239HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 1.3%CVE-2022-43907HIGHIBM Security Guardium command executionEPSS 1.3%CVE-2023-3939CRITICALMultiple command injection in ZkTeco-based OEM devicesEPSS 1.3%CVE-2025-47856HIGHTwo improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoiEPSS 1.3%CVE-2023-23779MEDIUMMultiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb verEPSS 1.3%CVE-2024-6507HIGHDeep Lake Kaggle command injectionEPSS 1.3%CVE-2025-14204MEDIUMTykoDev cherry-studio-TykoFork OAuth Server Discovery oauth-authorization-server redirectToAuthorization os command injectionEPSS 1.3%