Fallos del tipo CWE-78

4645 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-22280HIGHMAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancEPSS 1.0%CVE-2022-42053HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parEPSS 1.0%CVE-2025-25053HIGHOS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitraryEPSS 1.0%CVE-2021-3769HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 1.0%CVE-2025-28256CRITICALAn issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /liEPSS 1.0%CVE-2026-44168HIGHMariaDB: wsrep SST unsafe parameter handling on the donor sideEPSS 1.0%CVE-2022-1359MEDIUMCambium Networks cnMaestro Path TraversalEPSS 1.0%CVE-2026-27565CRITICALRemote code execution via uploading a malicious IODD fileEPSS 1.0%CVE-2023-41281MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41282MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-44304HIGH Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploEPSS 1.0%CVE-2023-41283MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2026-48554HIGHNagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro SubstitutionEPSS 1.0%CVE-2026-48553HIGHNagios Core / XI Authenticated RCE via Custom-Variable Macro InjectionEPSS 1.0%CVE-2020-7804MEDIUMActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShelEPSS 1.0%CVE-2025-41427HIGHWRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command InjectEPSS 1.0%CVE-2025-27804MEDIUMOS Command Injection Vulnerability in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 1.0%CVE-2023-47563HIGHVideo StationEPSS 1.0%CVE-2024-51008HIGHNetgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerEPSS 1.0%CVE-2024-51009HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulneraEPSS 1.0%