Falhas do tipo CWE-77

2.834 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-15366MEDIUMIMAP command injection in user-controlled commandsEPSS 0.4%CVE-2024-48142HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access anEPSS 0.4%CVE-2024-48140HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackeEPSS 0.4%CVE-2025-25793MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.EPSS 0.4%CVE-2025-25813MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.EPSS 0.4%CVE-2025-25797MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.EPSS 0.4%CVE-2025-25802MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.EPSS 0.4%CVE-2025-25796MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.EPSS 0.4%CVE-2025-25794MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.EPSS 0.4%CVE-2024-34713LOWsshproxy vulnerable to SSH option injectionEPSS 0.4%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.4%CVE-2026-21638HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2024-38903MEDIUMH3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.EPSS 0.4%CVE-2024-56086HIGHAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the bEPSS 0.4%CVE-2025-64090CRITICALAuthenticated Remote Code Execution in device hostnameEPSS 0.4%CVE-2024-22246HIGHVMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious acEPSS 0.4%CVE-2024-51317MEDIUMAn issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize functionEPSS 0.4%CVE-2024-53672MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.4%CVE-2025-56426MEDIUMAn issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the priEPSS 0.4%CVE-2023-49587MEDIUMCommand Injection vulnerability in SAP Solution ManagerEPSS 0.4%