Weaknesses of type CWE-78

4,606 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-48664HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2023-48662HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2023-48663HIGH Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could EPSS 1.7%CVE-2024-27772HIGHUnitronics Unistream Unilogic – Versions prior to 1.35.227 CWE-78: 'OS Command Injection'EPSS 1.7%CVE-2024-29185CRITICALFreeScout OS Command Injection vulnerabilityEPSS 1.7%CVE-2021-33532HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2021-33530HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2024-24325CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setParenEPSS 1.7%CVE-2024-24332CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilteEPSS 1.7%CVE-2021-33533HIGHWEIDMUELLER: WLAN devices affected by OS Command Injection vulnerabilityEPSS 1.7%CVE-2022-37901HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2022-37899HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2024-23059CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username parameter in the setDdnEPSS 1.7%CVE-2022-37902HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2024-23061CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute parameter in the setSchedEPSS 1.7%CVE-2022-37900HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.7%CVE-2026-9717HIGHCWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized EPSS 1.7%CVE-2026-2630HIGH[R1] Stand-alone Security Patches Available for Tenable Security Center versions 6.5.1, 6.6.0 and 6.7.2: SC-202602.1 + SC-202602.2EPSS 1.7%CVE-2025-56498MEDIUMAn OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp pEPSS 1.7%CVE-2026-40517HIGHradare2 < 6.1.4 Command Injection via PDB Parser Symbol NamesEPSS 1.7%