Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2020-12774HIGHD-Link DSL-7740C - Command InjectionEPSS 0.4%CVE-2019-1883HIGHCisco Integrated Management Controller CLI Command Injection VulnerabilityEPSS 0.4%CVE-2024-27920HIGHUnsigned code template execution through workflows in projectdiscovery/nucleiEPSS 0.4%CVE-2026-75364MEDIUMComfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitiEPSS 0.4%CVE-2025-30241HIGHOS Command Injection in Web Interface in Multiple TP-Link Aginet DevicesEPSS 0.4%CVE-2026-18824HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-42924HIGHBIG-IP iControl SOAP vulnerabilityEPSS 0.4%CVE-2025-30076HIGHKoha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.EPSS 0.4%CVE-2022-47210HIGHThe default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, hoEPSS 0.4%CVE-2025-58059CRITICALValtimo scripting engine can be used to gain access to sensitive data or resourcesEPSS 0.4%CVE-2026-32010MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via sort --compress-program ParameterEPSS 0.4%CVE-2020-3457MEDIUMCisco FXOS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-15986MEDIUMCisco Unity Express Command Injection VulnerabilityEPSS 0.4%CVE-2023-28767HIGHThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX serieEPSS 0.4%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.4%CVE-2026-87741HIGHConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' ParameterEPSS 0.4%CVE-2025-63408MEDIUMLocal Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to EPSS 0.4%CVE-2025-27614HIGHGitk allows arbitrary command executionEPSS 0.4%CVE-2022-26868MEDIUMDell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potenEPSS 0.4%CVE-2025-50974MEDIUMThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorpEPSS 0.4%