Fallos del tipo CWE-78

4665 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2018-19639MEDIUMCode execution if run with command line switch -vEPSS 0.5%CVE-2026-16856HIGHIBM i is Affected By Multiple Vulnerabilities in Domain Name SystemEPSS 0.5%CVE-2026-84085HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-53455HIGHBlueprint Studio Git credential helper command injectionEPSS 0.5%CVE-2026-16844HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-14277MEDIUMIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.5%CVE-2026-16848HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-82804HIGHApache DolphinScheduler: Command Injection in the Alert Script PluginEPSS 0.5%CVE-2026-16842HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-17186CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2024-2742MEDIUMOS Command Injection in Planet IGS-4215-16T2SEPSS 0.5%CVE-2025-46422HIGHDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2023-27999HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allowEPSS 0.5%CVE-2025-46423HIGHDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2025-20161MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2023-26210HIGHMultiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability inEPSS 0.5%CVE-2026-62943HIGHbtrbk: SSH Command Filter Bypass in ssh_filter_btrbk.shEPSS 0.5%CVE-2025-67034HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.5%CVE-2023-20175HIGHA vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on theEPSS 0.5%CVE-2024-24426HIGHReachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackeEPSS 0.5%