Falhas do tipo CWE-78

4.653 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-33529HIGHILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execEPSS 0.9%CVE-2026-42215HIGHGitPython: Command injection via Git options bypassEPSS 0.9%CVE-2025-8645MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8648MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-9661HIGHOS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23/24/26/28EPSS 0.9%CVE-2025-8644MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8647MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2026-91006HIGHApache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)EPSS 0.9%CVE-2025-23237MEDIUMImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE aEPSS 0.9%CVE-2025-8646MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8643MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-53695CRITICALOS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' usEPSS 0.9%CVE-2022-48070HIGHPhicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade fEPSS 0.9%CVE-2025-15101HIGHAn OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administratoEPSS 0.9%CVE-2022-48072HIGHPhicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade funEPSS 0.9%CVE-2025-69269HIGHSpectrum command injection in NCM serviceEPSS 0.9%CVE-2024-5670CRITICALSoftnext Mail SQR Expert and Mail Archiving Expert - OS Command InjectionEPSS 0.9%CVE-2024-47133HIGHUD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administratEPSS 0.9%CVE-2024-22222HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated maliciouEPSS 0.9%CVE-2026-34176HIGHKnowledge Appliance mode iControl REST vulnerabilityEPSS 0.9%