Falhas do tipo CWE-78

4.623 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-24326CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStEPSS 1.6%CVE-2024-24327CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpEPSS 1.6%CVE-2024-11007CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11006CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11005CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-8808HIGHCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-8809HIGHCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-22942CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanEPSS 1.6%CVE-2022-27616HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DisEPSS 1.6%CVE-2024-23058CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069CfEPSS 1.6%CVE-2024-45893HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.6%CVE-2024-45889HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.6%CVE-2024-23057HIGHTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg fuEPSS 1.6%CVE-2023-22598HIGH InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerEPSS 1.6%CVE-2021-35047CRITICALPrivileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.6%CVE-2024-52018HIGHNetgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnEPSS 1.6%CVE-2026-79792MEDIUMzackees transcribe-anything Yt-dlp Download ytldp_download.py ytdlp_download os command injectionEPSS 1.6%CVE-2024-52019HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vuEPSS 1.6%CVE-2018-18600HIGHThe remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.EPSS 1.6%CVE-2020-4066LOWCommand Injection in Limdu trainBatch functionEPSS 1.6%