Fallos del tipo CWE-78

4645 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-12763MEDIUMCommand injection vulnerability allowing arbitrary command execution on WindowsEPSS 0.9%CVE-2026-46394HIGHHAX CMS Vulnerable to Command Injection using Git.phpEPSS 0.9%CVE-2025-7724HIGHUnauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.9%CVE-2020-1609HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv6 packets and arbitrarily execute commands on the target device.EPSS 0.9%CVE-2026-75122HIGHPLANET GS-4210-16P2S V3 Command Injection via httpuploadcert.cgiEPSS 0.9%CVE-2026-14448HIGHAuthenticated RCE in system_certificates viewEPSS 0.9%CVE-2024-20424CRITICALA vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower ManagemeEPSS 0.9%CVE-2023-25617CRITICALOS Command Execution vulnerability in SAP Business Objects Business Intelligence Platform (Adaptive Job Server)EPSS 0.9%CVE-2026-6204HIGHLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config EPSS 0.9%CVE-2023-3570HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2025-70831CRITICALA Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The application fails to properEPSS 0.9%CVE-2023-24837HIGHHGiga PowerStation - Command InjectionEPSS 0.9%CVE-2022-38387HIGHIBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbitrary commands on theEPSS 0.9%CVE-2023-53948CRITICALLilac-Reloaded for Nagios 2.0.8 Remote Code Execution via AutodiscoveryEPSS 0.9%CVE-2026-33412MEDIUMVim affected by Command injection via newline in glob()EPSS 0.9%CVE-2026-23855HIGHDell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, coEPSS 0.9%CVE-2026-28291HIGHsimple-git has Command Execution via Option-Parsing BypassEPSS 0.9%CVE-2026-34110CRITICALGuardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.phpEPSS 0.9%CVE-2026-34114CRITICALGuardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.phpEPSS 0.9%CVE-2026-34106CRITICALGuardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.phpEPSS 0.9%