Falhas do tipo CWE-78

4.618 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-48664HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2023-48663HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2023-48662HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2024-27772HIGHUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-78: 'OS Command Injection'EPSS 1.7%CVE-2024-29185CRITICALFreeScout OS Command Injection vulnerabilityEPSS 1.7%CVE-2021-33532HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2024-24325CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParenEPSS 1.7%CVE-2021-33530HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2024-24332CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilteEPSS 1.7%CVE-2021-33533HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2022-37901HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2022-37899HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2022-37902HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2024-23059CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnEPSS 1.7%CVE-2024-23061CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setSchedEPSS 1.7%CVE-2022-37900HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2026-9717HIGHCWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized EPSS 1.7%CVE-2026-2630HIGH[R1] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2EPSS 1.7%CVE-2025-56498MEDIUMAn OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp pEPSS 1.7%CVE-2026-40517HIGHradare2 < 6.1.4 Command Injection via PDB Parser Symbol NamesEPSS 1.7%