CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-78 là gì?

MITRE CWE

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Xác minh để phân tích mục CWE này

Bước xác minh ngắn giúp bảo vệ nguồn dữ liệu chính thức và hạn chế việc gọi AI tự động.

Định nghĩa MITRE gốc (tiếng Anh)

MITRE CWE

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

This weakness can lead to a vulnerability in environments in which the attacker does not have direct access to the operating system, such as in web applications. Alternately, if the weakness occurs in a privileged program, it could allow the attacker to specify commands that normally would not be accessible, or to call alternate commands with privileges that the attacker does not have. The problem is exacerbated if the compromised process does not follow the principle of least privilege, because the attacker-controlled commands may run with special system privileges that increases the amount of damage. There are at least two subtypes of OS command injection: - The application intends to execute a single, fixed program that is under its own control. It intends to use externally-supplied inputs as arguments to that program. For example, the program might use system("nslookup [HOSTNAME]") to run nslookup and allow the user to supply a HOSTNAME, which is used as an argument. Attackers cannot prevent nslookup from executing. However, if the program does not remove command separators from the HOSTNAME argument, attackers could place the separators into the arguments, which allows them to execute their own program after nslookup has finished executing. - The application accepts an input that it uses to fully select which program to run, as well as which commands to use. The application simply redirects this entire command to the operating system. For example, the program might use "exec([COMMAND])" to execute the [COMMAND] that was supplied by the user. If the COMMAND is under attacker control, then the attacker can execute arbitrary commands or programs. If the command is being executed using functions like exec() and CreateProcess(), the attacker might not be able to combine multiple commands together in the same line. From a weakness standpoint, these variants represent distinct programmer errors. In the first variant, the programmer clearly intends that input from untrusted parties will be part of the arguments in the command to be executed. In the second variant, the programmer does not intend for the command to be accessible to any untrusted party, but the programmer probably has not accounted for alternate ways in which malicious attackers can provide input.

Mô tả chi tiết

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Đặc điểm

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Giai đoạn hình thành

  • Hiện thực hóa

Tác động thường gặp

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Tính bí mật, Tính toàn vẹn, Tính sẵn sàng, Chống chối bỏ

    Thực thi mã hoặc lệnh trái phép, Từ chối dịch vụ: sập, thoát hoặc khởi động lại, Đọc tệp hoặc thư mục, Thay đổi tệp hoặc thư mục, Đọc dữ liệu ứng dụng, Thay đổi dữ liệu ứng dụng, Che giấu hoạt động

Biện pháp giảm thiểu

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Kiến trúc và thiết kế
  • Kiến trúc và thiết kế, Vận hành · Môi trường cô lập (sandbox/jail)Hiệu quả: Hạn chế
  • Kiến trúc và thiết kế · Giảm bề mặt tấn công
  • Kiến trúc và thiết kế
  • Kiến trúc và thiết kế · Thư viện hoặc framework
  • Hiện thực hóa · Mã hóa ký tự đầu ra
  • Hiện thực hóa
  • Kiến trúc và thiết kế · Tham số hóa
  • Hiện thực hóa · Kiểm tra dữ liệu đầu vào
  • Kiến trúc và thiết kế · Áp đặt quy tắc bằng chuyển đổi
  • Vận hành · Gia cố quá trình biên dịch hoặc xây dựng
  • Vận hành · Gia cố môi trường
  • Hiện thực hóa
  • Vận hành · Môi trường cô lập (sandbox/jail)
  • Vận hành · Tường lửaHiệu quả: Khá
  • Kiến trúc và thiết kế, Vận hành · Gia cố môi trường
  • Vận hành, Hiện thực hóa · Gia cố môi trường

Phương pháp phát hiện

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
  • Phân tích tĩnh tự động
  • Phân tích động tự độngHiệu quả: Khá
  • Phân tích tĩnh thủ côngHiệu quả: Cao
  • Phân tích tĩnh tệp nhị phân hoặc bytecode tự độngHiệu quả: Cao
  • Phân tích động với diễn giải kết quả tự độngHiệu quả: SOAR một phần
  • Phân tích động với diễn giải kết quả thủ côngHiệu quả: SOAR một phần
  • Phân tích tĩnh mã nguồn thủ côngHiệu quả: Cao
  • Phân tích tĩnh mã nguồn tự độngHiệu quả: Cao
  • Rà soát kiến trúc hoặc thiết kếHiệu quả: Cao

Lỗ hổng điển hình

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Nguồn và tài liệu tham khảo

Tham chiếu

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard