Fallos del tipo CWE-78

4652 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-36922CRITICALOS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)EPSS 0.8%CVE-2026-16287HIGHRoot Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-updateEPSS 0.8%CVE-2026-8301HIGHOS Command Injection in TUBITAK BILGEM's Pardus-boot-repairEPSS 0.8%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-76714HIGHAuthenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.8%CVE-2023-34343HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2025-55055MEDIUMCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 0.8%CVE-2023-34334HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2025-29887HIGHQuRouter 2.5EPSS 0.8%CVE-2023-25759MEDIUMOS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to runEPSS 0.8%CVE-2024-0168HIGH Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potenEPSS 0.8%CVE-2025-7723HIGHAuthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.8%CVE-2024-0170HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could EPSS 0.8%CVE-2026-35160MEDIUMDell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command (EPSS 0.8%CVE-2020-1605HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.EPSS 0.8%CVE-2026-15427HIGHOS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800vEPSS 0.8%CVE-2024-1628HIGHOS command injection vulnerabilities in GE HealthCare ultrasound devicesEPSS 0.8%CVE-2026-85168HIGHn8n before 1.123.73 Remote Code Execution via Git NodeEPSS 0.8%CVE-2026-73623HIGHGitPython before 3.1.54 Remote Code Execution via --templateEPSS 0.8%CVE-2026-21267HIGHDreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.8%