Fallos del tipo CWE-78

4652 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-33238HIGHCommand-injection Vulnerability in Certificate ManagementEPSS 0.8%CVE-2026-14958CRITICALOS command injection in IBM Aspera FaspexEPSS 0.8%CVE-2019-16639CRITICALAn issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attaEPSS 0.8%CVE-2026-43685HIGHA Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating sEPSS 0.8%CVE-2023-46117CRITICALInadequate validation of retrieved subdomains may lead to a Remote Code Execution in reconFTWEPSS 0.8%CVE-2026-44194CRITICALOPNsense: RCE on user managmentEPSS 0.8%CVE-2026-46735HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS EPSS 0.8%CVE-2024-6091CRITICALShell Command Denylist Bypass in significant-gravitas/autogptEPSS 0.8%CVE-2023-25555MEDIUM A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists thaEPSS 0.8%CVE-2026-72885NONEDokploy: Authenticated Command Injection in Dokploy Dockerfile BuilderEPSS 0.8%CVE-2026-29607HIGHOpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper PersistenceEPSS 0.8%CVE-2018-0221—A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perforEPSS 0.8%CVE-2026-16022HIGHCommand Injection in @oblique/cliEPSS 0.8%CVE-2026-44191HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settingsEPSS 0.8%CVE-2024-51005HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi.EPSS 0.8%CVE-2024-38882CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.8%CVE-2024-46486HIGHTP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.EPSS 0.8%CVE-2024-51252HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.8%CVE-2024-21906MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2023-28627HIGHOS Command Injection via GIT_PATH in pymedusaEPSS 0.8%