Weaknesses of type CWE-78

4,612 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2020-4066LOWCommand Injection in Limdu trainBatch functionEPSS 1.6%CVE-2025-26817CRITICALNetwrix Password Secure 9.2.0.32454 allows OS command injection.EPSS 1.6%CVE-2024-42736HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. AuEPSS 1.6%CVE-2024-28187HIGHOS Command Injection Vulnerability in SOY CMSEPSS 1.6%CVE-2026-24517HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.6%CVE-2022-48337CRITICALGNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etagEPSS 1.6%CVE-2024-0714MEDIUMMiczFlor RPi-Jukebox-RFID HTTP Request userScripts.php os command injectionEPSS 1.6%CVE-2024-24331CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiSEPSS 1.6%CVE-2026-11556HIGHTenda F451 Web Management WriteFacMac formWriteFacMac os command injectionEPSS 1.6%CVE-2022-37912HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.6%CVE-2024-3659CRITICALCommand injection in KAON AR2140 routersEPSS 1.6%CVE-2026-45695CRITICALKopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is usedEPSS 1.6%CVE-2026-2035MEDIUMDeciso OPNsense diag_backup.php filename Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2025-45042CRITICALTenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.EPSS 1.6%CVE-2023-6201HIGHCommand Injection in Univera Panorama FrameworkEPSS 1.6%CVE-2024-45827HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmwareEPSS 1.6%CVE-2024-41153HIGHCommand injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commEPSS 1.6%CVE-2024-43650CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.6%CVE-2024-57019HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAEPSS 1.6%CVE-2024-57013HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch" parameter in setSchEPSS 1.6%