Weaknesses of type CWE-78

4,610 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2022-44567CRITICALA command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalEPSS 1.7%CVE-2022-34447HIGH PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote atEPSS 1.7%CVE-2025-32002CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard diEPSS 1.7%CVE-2026-72580CRITICALduhow xiaoai-patch - OS Command Injection in /mute and /unmute EndpointsEPSS 1.7%CVE-2024-3196MEDIUMMailCleaner SOAP Service dumpConfiguration os command injectionEPSS 1.7%CVE-2022-3276HIGHPuppetlabs-mysql Command InjectionEPSS 1.7%CVE-2026-18482CRITICALCVE-2026-18482EPSS 1.7%CVE-2024-31473CRITICALThere is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code executiEPSS 1.7%CVE-2021-3058HIGHPAN-OS: OS Command Injection Vulnerability in Web Interface XML APIEPSS 1.6%CVE-2021-47903HIGHLiteSpeed Web Server Enterprise 5.4.11 - Command InjectionEPSS 1.6%CVE-2026-10144HIGHRsbuild < 2.0.9 Command Injection via openBrowser() URL HandlingEPSS 1.6%CVE-2024-42742HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRuleEPSS 1.6%CVE-2024-42738HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. AutheEPSS 1.6%CVE-2024-42743HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . AEPSS 1.6%CVE-2024-42744HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUserEPSS 1.6%CVE-2023-6078HIGHOS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023EPSS 1.6%CVE-2026-56379CRITICALImageMagick - Command Injection via SVG DecoderEPSS 1.6%CVE-2018-15722—The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man iEPSS 1.6%CVE-2023-52026CRITICALTOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parEPSS 1.6%