Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-11861CRITICALCommand injection in EnerSys AMPA 22.09 and prior versionsEPSS 1.4%CVE-2023-33235HIGHMXsecurity Command Injection VulnerabilityEPSS 1.4%CVE-2024-24897HIGHRemote command execution in A-Tune-CollectorEPSS 1.4%CVE-2026-84387MEDIUMA improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSanEPSS 1.4%CVE-2022-0999HIGHmySCADA myPRO Command InjectionEPSS 1.4%CVE-2024-47460CRITICALUnauthenticated Command Injection Vulnerability in the CLI Service Accessed by the PAPI ProtocolEPSS 1.4%CVE-2026-3964MEDIUMOpenAkita Chat API Endpoint shell.py run os command injectionEPSS 1.4%CVE-2026-22103CRITICALCommand injection in NPC start web endpointEPSS 1.4%CVE-2021-34592HIGHBender Charge Controller: Command injection via Web interfaceEPSS 1.4%CVE-2026-22095CRITICALCommand injection in diagnosis web endpointEPSS 1.4%CVE-2025-58428CRITICALCommand Injection in Veeder-Root TLS4B Automatic Tank Gauge SystemEPSS 1.4%CVE-2025-1229MEDIUMolajowon Loggrove page os command injectionEPSS 1.4%CVE-2024-36783CRITICALTOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost functEPSS 1.4%CVE-2019-14868HIGHIn ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to overrideEPSS 1.4%CVE-2022-45104HIGH Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. EPSS 1.4%CVE-2024-7397CRITICALUnauthenticated Command InjectionEPSS 1.4%CVE-2022-45094HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the WebEPSS 1.4%CVE-2025-59736CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%CVE-2025-59738CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%CVE-2025-59739CRITICALMultiple vulnerabilities in AndSoft's e-TMSEPSS 1.4%