Fallos del tipo CWE-78

4653 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-45777CRITICALOpen XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command InjectionEPSS 0.7%CVE-2023-32568HIGHAn issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application doeEPSS 0.7%CVE-2024-8881MEDIUMA post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and EPSS 0.7%CVE-2024-36103MEDIUMOS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent atEPSS 0.7%CVE-2023-23694MEDIUM Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attackEPSS 0.7%CVE-2024-20358MEDIUMA vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco FirepEPSS 0.7%CVE-2026-46624CRITICALTwenty: SQL Injection via the timeZone fieldEPSS 0.7%CVE-2022-26413HIGHA command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticatedEPSS 0.7%CVE-2026-58236MEDIUMOS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP PlatformEPSS 0.7%CVE-2025-52994MEDIUMgif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7EPSS 0.7%CVE-2026-39938CRITICALCacti: Unauthenticated RCE on Graph ImageEPSS 0.7%CVE-2024-55904HIGHIBM DevOps Deploy / IBM UrbanCode Deploy command injectionEPSS 0.7%CVE-2026-27602HIGHModoboa has an OS Command InjectionEPSS 0.7%CVE-2025-43941HIGHDell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.7%CVE-2026-48787HIGHgin-vue-admin vulnerable to RCEEPSS 0.7%CVE-2026-63298HIGHLXD arbitrary lxc.conf directive injection via NVIDIA instance configurationEPSS 0.7%CVE-2026-77084HIGHn8n before 1.123.69 Remote Code Execution via Git Node Configuration ValuesEPSS 0.7%CVE-2024-26258HIGHOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OEPSS 0.7%CVE-2024-26012MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4EPSS 0.7%CVE-2026-27965HIGHVitess users with backup storage access can gain unauthorized access to production deployment environmentsEPSS 0.7%