Weaknesses of type CWE-78

4,611 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-24326CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStEPSS 1.6%CVE-2024-24327CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpEPSS 1.6%CVE-2024-11007CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11006CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-11005CRITICALCommand injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.EPSS 1.6%CVE-2024-8808HIGHCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-8809HIGHCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2024-22942CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName parameter in the setWanEPSS 1.6%CVE-2022-27616HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DisEPSS 1.6%CVE-2024-23058CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass parameter in the setTr069CfEPSS 1.6%CVE-2024-45893HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.6%CVE-2024-45889HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.6%CVE-2024-23057HIGHTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter in the setNtpCfg fuEPSS 1.6%CVE-2023-22598HIGH InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerEPSS 1.6%CVE-2021-35047CRITICALPrivileged Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.6%CVE-2024-52018HIGHNetgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnEPSS 1.6%CVE-2026-79792MEDIUMzackees transcribe-anything Yt-dlp Download ytldp_download.py ytdlp_download os command injectionEPSS 1.6%CVE-2024-52019HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vuEPSS 1.6%CVE-2018-18600HIGHThe remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parameter.EPSS 1.6%CVE-2025-15060CRITICALclaude-hovercraft executeClaudeCode Command Injection Remote Code Execution VulnerabilityEPSS 1.6%