Weaknesses of type CWE-78

4,609 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-8869LOWTOTOLINK A720R exportOvpn os command injectionEPSS 1.7%CVE-2022-43971HIGHArbitrary code execution in Linksys WUMC710EPSS 1.7%CVE-2023-33013HIGHA post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an auEPSS 1.7%CVE-2026-53932HIGHwnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection')EPSS 1.7%CVE-2025-34116HIGHIPFire < 2.19 Core Update 101 proxy.cgi RCEEPSS 1.7%CVE-2025-65791CRITICALZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user input directly to theEPSS 1.7%CVE-2026-59687HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management InterfaceEPSS 1.7%CVE-2026-59688HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore FunctionalityEPSS 1.7%CVE-2026-59686HIGHProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management InterfaceEPSS 1.7%CVE-2026-53975CRITICALOpenChamber 1.11.7 Unauthenticated RCE via /api/fs/execEPSS 1.7%CVE-2025-58763HIGHTautulli vulnerable to Authenticated Remote Code Execution via Command InjectionEPSS 1.7%CVE-2026-0286MEDIUMPAN-OS: Authenticated Command Injection in CLIEPSS 1.7%CVE-2024-39402HIGHAdobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 1.7%CVE-2024-39401HIGHAdobe Commerce | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 1.7%CVE-2026-24101CRITICALAn issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into suEPSS 1.7%CVE-2023-47105HIGHexec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without autEPSS 1.7%CVE-2023-52028CRITICALTOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setTracerouteCfg funEPSS 1.7%CVE-2023-52029CRITICALTOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the setDiagnosisCfg funcEPSS 1.7%CVE-2025-66178MEDIUMA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 througEPSS 1.7%CVE-2026-0782HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%