Weaknesses of type CWE-78

4,608 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-35506HIGHELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processinEPSS 1.7%CVE-2026-59764HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploEPSS 1.7%CVE-2026-61376HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerabiliEPSS 1.7%CVE-2026-50043HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If thiEPSS 1.7%CVE-2026-49815HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 1.7%CVE-2026-34188HIGHOS Command Injection in Event Response ExecutionEPSS 1.7%CVE-2024-7448HIGHMagnet Forensics AXIOM Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2022-42055MEDIUMMultiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroEPSS 1.7%CVE-2026-16468HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.7%CVE-2025-64153MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, EPSS 1.7%CVE-2023-51625HIGHD-Link DCS-8300LHV2 ONVIF SetSystemDateAndTime Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-39091HIGHAn OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers withiEPSS 1.7%CVE-2022-37915CRITICALA vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attEPSS 1.7%CVE-2024-4253HIGHCommand Injection in gradio-app/gradioEPSS 1.7%CVE-2026-44170MEDIUMMariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URLEPSS 1.7%CVE-2020-2492HIGHIf exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP SysteEPSS 1.7%CVE-2024-50853HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.EPSS 1.7%CVE-2024-50852HIGHTenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.EPSS 1.7%CVE-2024-24333CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclEPSS 1.7%CVE-2012-10033CRITICALNarcissus backend.php Image Configuration Command InjectionEPSS 1.7%