CWE-78 · 5 962 записей
Внедрение команд ОС
Почему это происходит?
Пользовательский ввод вставляется в команду оболочки как текст. Оболочка может интерпретировать специальные символы во вводе как часть команды.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
const host = req.body.host;exec("ping -c 1 " + host, onResult);Исправленный код
const host = req.body.host;if (!/^[a-z0-9.-]{1,253}$/i.test(host)) return res.sendStatus(400);execFile("ping", ["-c", "1", host], onResult);Как предотвратить
- 01Вместо запуска через оболочку используйте API, принимающие аргументы массивом.
- 02Проверяйте ввод по списку разрешённых значений (например, только формат доменного имени).
- 03По возможности используйте библиотечную функцию вместо команды ОС.
CVE этого класса
5 962 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2026-10520Готовый эксплойт | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Критическая10,0 | KEV | 99,9 % | 9 июн. 2026 г. |
99Срочно | CVE-2021-1498Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 100,0 % | 6 мая 2021 г. |
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2019-16920Готовый эксплойт | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.dlink · dir-655 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 27 сент. 2019 г. |
99Срочно | CVE-2022-44877Готовый эксплойт | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commacontrol-webpanel · webpanel · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 янв. 2023 г. |
99Срочно | CVE-2020-8515Готовый эксплойт | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executidraytek · vigor2960 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 1 февр. 2020 г. |
99Срочно | CVE-2020-9054Готовый эксплойт | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 4 мар. 2020 г. |
99Срочно | CVE-2024-4577Готовый эксплойт | Argument Injection in PHP-CGIphp · php · CWE-78 | Критическая9,8 | KEV | 100,0 % | 9 июн. 2024 г. |
99Срочно | CVE-2020-25506Готовый эксплойт | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary dlink · dns-320 firmware · CWE-78 | Критическая9,8 | KEV | 100,0 % | 2 февр. 2021 г. |
99Срочно | CVE-2019-10149Готовый эксплойт | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Критическая9,8 | KEV | 100,0 % | 5 июн. 2019 г. |
99Срочно | CVE-2018-10562Готовый эксплойт | An issue was discovered on Dasan GPON home routers.dasannetworks · gpon router firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 3 мая 2018 г. |
99Срочно | CVE-2022-30525Готовый эксплойт | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 12 мая 2022 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2021-1497Готовый эксплойт | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Критическая9,8 | KEV | 99,9 % | 6 мая 2021 г. |
99Срочно | CVE-2024-45519Готовый эксплойт | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Критическая9,8 | KEV | 99,9 % | 2 окт. 2024 г. |
99Срочно | CVE-2021-36260Готовый эксплойт | A command injection vulnerability in the web server of some Hikvision product.hikvision · ds-2cd2026g2-iu\/sl firmware · CWE-78 | Критическая9,8 | KEV | 99,9 % | 22 сент. 2021 г. |
99Срочно | CVE-2021-35394Готовый эксплойт | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.realtek · rtl819x jungle software development kit · CWE-78 | Критическая9,8 | KEV | 99,9 % | 16 авг. 2021 г. |
99Срочно | CVE-2019-15107Готовый эксплойт | An issue was discovered in Webmin <=1.920.webmin · webmin · CWE-78 | Критическая9,8 | KEV | 99,7 % | 15 авг. 2019 г. |
99Срочно | CVE-2020-16846Готовый эксплойт | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Критическая9,8 | KEV | 99,6 % | 6 нояб. 2020 г. |
99Срочно | CVE-2023-28771Готовый эксплойт | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Критическая9,8 | KEV | 99,3 % | 24 апр. 2023 г. |
99Срочно | CVE-2020-7247Готовый эксплойт | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Критическая9,8 | KEV | 99,0 % | 29 янв. 2020 г. |
99Срочно | CVE-2024-9463Готовый эксплойт | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Критическая9,9 | KEV | 98,5 % | 9 окт. 2024 г. |
99Срочно | CVE-2024-50603Готовый эксплойт | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996.aviatrix · controller · CWE-78 | Критическая9,8 | KEV | 98,5 % | 7 янв. 2025 г. |
98Срочно | CVE-2022-29303Готовый эксплойт | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.contec · sv-cpt-mc310 firmware · CWE-78 | Критическая9,8 | KEV | 98,0 % | 12 мая 2022 г. |
98Срочно | CVE-2023-25280Готовый эксплойт | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with tdlink · dir-820l firmware · CWE-78 | Критическая9,8 | KEV | 97,9 % | 15 мар. 2023 г. |
- CVE-2026-10520100Срочно
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · standalone sentry9 июн. 2026 г.
- CVE-2021-149899Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2019-1692099Срочно
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dir-655 firmware27 сент. 2019 г.
- CVE-2022-4487799Срочно
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %control-webpanel · webpanel5 янв. 2023 г.
- CVE-2020-851599Срочно
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %draytek · vigor2960 firmware1 февр. 2020 г.
- CVE-2020-905499Срочно
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · nas326 firmware4 мар. 2020 г.
- CVE-2024-457799Срочно
Argument Injection in PHP-CGI
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php9 июн. 2024 г.
- CVE-2020-2550699Срочно
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dns-320 firmware2 февр. 2021 г.
- CVE-2019-1014999Срочно
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %exim · exim5 июн. 2019 г.
- CVE-2018-1056299Срочно
An issue was discovered on Dasan GPON home routers.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dasannetworks · gpon router firmware3 мая 2018 г.
- CVE-2022-3052599Срочно
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %zyxel · usg flex 100w firmware12 мая 2022 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2021-149799Срочно
Cisco HyperFlex HX Command Injection Vulnerabilities
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cisco · hyperflex hx data platform6 мая 2021 г.
- CVE-2024-4551999Срочно
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %synacor · zimbra collaboration suite2 окт. 2024 г.
- CVE-2021-3626099Срочно
A command injection vulnerability in the web server of some Hikvision product.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %hikvision · ds-2cd2026g2-iu\/sl firmware22 сент. 2021 г.
- CVE-2021-3539499Срочно
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %realtek · rtl819x jungle software development kit16 авг. 2021 г.
- CVE-2019-1510799Срочно
An issue was discovered in Webmin <=1.920.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %webmin · webmin15 авг. 2019 г.
- CVE-2020-1684699Срочно
An issue was discovered in SaltStack Salt through 3002.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %saltstack · salt6 нояб. 2020 г.
- CVE-2023-2877199Срочно
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %zyxel · atp100 firmware24 апр. 2023 г.
- CVE-2020-724799Срочно
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %openbsd · opensmtpd29 янв. 2020 г.
- CVE-2024-946399Срочно
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 99 %paloaltonetworks · expedition9 окт. 2024 г.
- CVE-2024-5060399Срочно
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %aviatrix · controller7 янв. 2025 г.
- CVE-2022-2930398Срочно
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %contec · sv-cpt-mc310 firmware12 мая 2022 г.
- CVE-2023-2528098Срочно
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with t
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %dlink · dir-820l firmware15 мар. 2023 г.