Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-67738HIGHsquid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache ManagerEPSS 0.4%CVE-2026-79761MEDIUMTermix: Command injection in SSH key deployment verificationEPSS 0.4%CVE-2026-34149LOWCoolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup JobsEPSS 0.4%CVE-2025-13686MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2025-13688MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2025-13687MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2020-3417MEDIUMCisco IOS XE Software Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2019-1732MEDIUMCisco NX-OS Software Remote Package Manager Command Injection VulnerabilityEPSS 0.4%CVE-2025-45378CRITICALDell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into EPSS 0.4%CVE-2026-81623MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-45626MEDIUMArcane: OS Command Injection in Volume Browser ListDirectory via path query parameterEPSS 0.4%CVE-2026-1345HIGHSecurity Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2026-45369HIGHpython-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication ProtocolEPSS 0.4%CVE-2022-33923MEDIUMDell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticaEPSS 0.4%CVE-2025-24936CRITICALInsufficient Validation of Input in the URLEPSS 0.4%CVE-2024-55021HIGHWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.EPSS 0.4%CVE-2026-9279HIGHShell command injection in LogseqEPSS 0.3%CVE-2026-50227MEDIUMMQTT WebSocket Command Execution Vulnerability in NitroSenseEPSS 0.3%CVE-2023-28805MEDIUMZCC on Linux privilege escalationEPSS 0.3%CVE-2026-20350MEDIUMCisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection VulnerabilityEPSS 0.3%