Weaknesses of type CWE-78

4,606 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-11900CRITICALHGiga|iSherlock - OS Command InjectionEPSS 1.8%CVE-2023-3267CRITICALWhen adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passeEPSS 1.8%CVE-2023-37927HIGHThe improper neutralization of special elements in the CGI program of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmwareEPSS 1.8%CVE-2026-4408CRITICALSamba: remote code execution in samrEPSS 1.8%CVE-2024-2662HIGHUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admin+) Command InjectionEPSS 1.7%CVE-2019-5071HIGHAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart DualEPSS 1.7%CVE-2022-41131HIGHApache Airflow Hive Provider vulnerability (command injection via hive_cli connection)EPSS 1.7%CVE-2025-34132CRITICALLILIN DVR Command Injection via NTPUpdate in dvr_boxEPSS 1.7%CVE-2024-52034CRITICALmySCADA myPRO OS Command InjectionEPSS 1.7%CVE-2020-8007CRITICALThe pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via thEPSS 1.7%CVE-2021-32524CRITICALQSAN Storage Manager - Command Injection-3EPSS 1.7%CVE-2025-34239HIGHAdvantech WebAccess/VPN < 1.1.5 Command Injection in AppManagementController.appUpgradeAction()EPSS 1.7%CVE-2023-39295HIGHQuMagieEPSS 1.7%CVE-2024-57011HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute" parameters in setScEPSS 1.7%CVE-2025-34042CRITICALBeward N100 IP Camera Remote Command ExecutionEPSS 1.7%CVE-2026-87911CRITICALRead-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-serverEPSS 1.7%CVE-2024-48826HIGHTenda AC7 v.15.03.06.44 ate_iwpriv_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2024-48825HIGHTenda AC7 v.15.03.06.44 ate_ifconfig_set has pre-authentication command injection allowing remote attackers to execute arbitrary code.EPSS 1.7%CVE-2022-4643MEDIUMdocconv pdf_ocr.go ConvertPDFImages os command injectionEPSS 1.7%CVE-2023-48662HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%