Fallos del tipo CWE-78

4627 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-24816MEDIUMset_term_title command injection in ipythonEPSS 1.3%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.3%CVE-2011-3178HIGHopenbuildservice webui code injectionEPSS 1.3%CVE-2025-37170HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2023-35019HIGHIBM Security Verify Governance command executionEPSS 1.3%CVE-2024-42757CRITICALCommand injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat functionEPSS 1.3%CVE-2025-56124HIGHOS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands viaEPSS 1.3%CVE-2025-50946MEDIUMOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.EPSS 1.3%CVE-2025-11005CRITICALTOTOLINK X6000R Unauthenticated Command Injection VulnerabilityEPSS 1.3%CVE-2026-62312HIGH9Router: Authenticated RCE via Unvalidated MCP Plugin ArgumentsEPSS 1.3%CVE-2026-44590CRITICALSherlock: Command Injection via pull_request_target in validate_modified_targets.ymlEPSS 1.3%CVE-2026-28292CRITICALsimple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCEEPSS 1.3%CVE-2022-24390HIGHAuthenticated Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.3%CVE-2026-24788HIGHRaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be exeEPSS 1.3%CVE-2024-12829HIGHArista NG Firewall ExecManagerImpl Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-8663MEDIUMOS Command Injection in Rapid7 InsightConnect RPM PluginEPSS 1.3%CVE-2026-8659MEDIUMOS Command Injection in Rapid7 InsightConnect SQLmap PluginEPSS 1.3%CVE-2026-8658MEDIUMOS Command Injection in Rapid7 InsightConnect Tcpdump PluginEPSS 1.3%CVE-2026-8664MEDIUMOS Command Injection in Rapid7 InsightConnect Finger PluginEPSS 1.3%CVE-2026-0630HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0EPSS 1.3%