Weaknesses of type CWE-78

4,613 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-57018HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setVpnAcEPSS 1.6%CVE-2024-57016HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" parameter in setVpnAcEPSS 1.6%CVE-2024-57015HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" parameter in setSchedEPSS 1.6%CVE-2024-57012HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setSchedEPSS 1.6%CVE-2024-57019HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit" parameter in setVpnAEPSS 1.6%CVE-2024-57022HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour" parameter in setWiFiEPSS 1.6%CVE-2024-57017HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" parameter in setVpnAcEPSS 1.6%CVE-2024-57021HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour" parameter in setWiFiEPSS 1.6%CVE-2024-26260CRITICALHgiga OAKlouds - Command InjectionEPSS 1.6%CVE-2022-33186CRITICALA vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated aEPSS 1.6%CVE-2026-48165HIGHMariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner sideEPSS 1.6%CVE-2022-39321HIGHGitHub Actions Runner vulnerable to Docker Command EscapingEPSS 1.6%CVE-2023-23362HIGHQTS, QuTS hero, QuTScloudEPSS 1.6%CVE-2026-19679HIGHImproper Input ValidationEPSS 1.6%CVE-2026-30809HIGHOS Command Injection in WebServerModuleDebug via Blacklist Bypass leads to Remote Code ExecutionEPSS 1.6%CVE-2026-9155HIGHOS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.EPSS 1.6%CVE-2026-30806HIGHOS Command Injection in Network Report leads to Remote Code ExecutionEPSS 1.6%CVE-2025-63916HIGHMyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properlyEPSS 1.6%CVE-2026-40855CRITICALCommand Injection in T-Mobile 5G Box IDU router via ping functionalityEPSS 1.6%CVE-2024-38644HIGHNotes Station 3EPSS 1.6%