Weaknesses of type CWE-78

4,608 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-23060CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg fuEPSS 1.7%CVE-2025-5952MEDIUMZend.To NSSDropoff.php exec os command injectionEPSS 1.7%CVE-2025-6559CRITICALSapido Wireless Router - OS Command InjectionEPSS 1.7%CVE-2023-3767CRITICALOS command injection on EasyPHP Webserver EPSS 1.7%CVE-2023-35762CRITICALOS Command Injection in INEA ME RTUEPSS 1.7%CVE-2026-40499HIGHradare2 < 6.1.4 Command Injection via PDB Parser print_gvars()EPSS 1.7%CVE-2026-68861HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 1.7%CVE-2025-34099CRITICALVICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth PasswordEPSS 1.7%CVE-2022-39951HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.EPSS 1.7%CVE-2026-49261CRITICALMariaDB server has unsafe parameter handling in `wsrep_notify_cmd`EPSS 1.7%CVE-2024-43651CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.7%CVE-2026-40079HIGHCacti: Command Injection via escape_command() no-op in RRDtool executionEPSS 1.7%CVE-2024-8807CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-24899HIGHCommand injection in aops-zeusEPSS 1.7%CVE-2026-45391HIGHLocal privilege escalation in Cribl Edge for LinuxEPSS 1.7%CVE-2024-8806CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0780HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0779HIGHALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0781HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-31977HIGHAdtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters EPSS 1.7%