Fallos del tipo CWE-78

4664 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-1513HIGHA potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a speciaEPSS 0.6%CVE-2025-55048CRITICALMultiple CWE-78EPSS 0.6%CVE-2024-5399HIGHOpenfind Mail2000 - OS Command InjectionEPSS 0.6%CVE-2024-5403HIGHASKEY 5G NR Small Cell - Command InjectionEPSS 0.6%CVE-2024-27778HIGHAn improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 thrEPSS 0.6%CVE-2025-53680MEDIUMAn improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in FortinEPSS 0.6%CVE-2025-53870MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 througEPSS 0.6%CVE-2025-54072HIGHyt-dlp allows `--exec` command injection when using placeholder on WindowsEPSS 0.6%CVE-2023-5677MEDIUMBrandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input EPSS 0.6%CVE-2026-28797HIGHRAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" ComponentEPSS 0.6%CVE-2025-27613LOWGitk can create and truncate files in the user's home directoryEPSS 0.6%CVE-2026-27635HIGHManyfold vulnerable to OS command injection via ZIP filename in f3d renderEPSS 0.6%CVE-2025-0119MEDIUMCortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VMEPSS 0.6%CVE-2026-23820HIGHInconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLIEPSS 0.6%CVE-2025-64755HIGH@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File WritesEPSS 0.6%CVE-2026-16672HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2026-55249MEDIUM@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template StringEPSS 0.6%CVE-2022-27482HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.EPSS 0.6%CVE-2024-31478MEDIUMMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful expEPSS 0.6%CVE-2024-49281MEDIUMWordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.5%