Falhas do tipo CWE-78

4.645 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-27356MEDIUMNETGEAR RAX30 logCtrl Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-28811CRITICALPossible command injection in Car Park Server in Carlo Gavazzi UWP3.0EPSS 1.2%CVE-2022-43483CRITICALCVE-2022-43483EPSS 1.2%CVE-2022-47911CRITICALCVE-2022-47911EPSS 1.2%CVE-2023-21413CRITICALRemote code execution vulnerability during the installation of ACAP applications on the Axis deviceEPSS 1.2%CVE-2022-47208HIGHThe “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticEPSS 1.2%CVE-2023-28702HIGHASUS RT-AC86U - Command InjectionEPSS 1.2%CVE-2021-42081CRITICALAuthenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355EPSS 1.2%CVE-2026-81476HIGHDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS CommEPSS 1.2%CVE-2024-2359CRITICALImproper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webuiEPSS 1.2%CVE-2024-42978CRITICALAn issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a craftedEPSS 1.2%CVE-2026-41876HIGHOS Command Injection in R-SOFT DMSEPSS 1.2%CVE-2026-14371HIGHThe Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to PowershelEPSS 1.2%CVE-2025-58062HIGHLSTM-Kirigaya's openmcp-client Vulnerable to RCE in MCP Authorization FlowEPSS 1.2%CVE-2023-23355MEDIUMQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVREPSS 1.2%CVE-2025-57799HIGHStreamVault can perform remote command executionEPSS 1.2%CVE-2026-16763MEDIUMlocalstack serverless-localstack Configuration index.js os command injectionEPSS 1.2%CVE-2022-40176—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 1.2%CVE-2023-29412CRITICALCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remEPSS 1.2%CVE-2022-2253CRITICALDistributed Data Systems WebHMI OS Command InjectionEPSS 1.2%