Weaknesses of type CWE-78

4,615 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-67438MEDIUMOliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety CheckEPSS 1.6%CVE-2023-44291HIGH Dell DM5500 5.14.0.0 contains an OS command injection vulnerability in the appliance. A remote attacker with high privileges could potentEPSS 1.6%CVE-2026-23699HIGHAP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exEPSS 1.6%CVE-2023-38027CRITICALSpotCam Co., Ltd. SpotCam Sense - Command InjectionEPSS 1.6%CVE-2023-22919HIGHThe post-authentication command injection vulnerability in the Zyxel NBG6604 firmware version V1.01(ABIR.0)C0 could allow an authenticated aEPSS 1.6%CVE-2022-48581HIGHA command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input aEPSS 1.6%CVE-2025-10619MEDIUMsequa-ai sequa-mcp OAuth Server Discovery node-oauth-client-provider.ts redirectToAuthorization os command injectionEPSS 1.6%CVE-2025-13700HIGHDreamFactory saveZipFile Command Injection Remote Code Execution VulnerabilityEPSS 1.6%CVE-2022-40929CRITICALXXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an iEPSS 1.6%CVE-2013-10053HIGHZPanel <= 10.0.0.2 htpasswd Module Username Command ExecutionEPSS 1.6%CVE-2024-31471CRITICALThere is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code eEPSS 1.6%CVE-2024-31472CRITICALThere are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code executioEPSS 1.6%CVE-2026-48385HIGHColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 1.6%CVE-2026-59680HIGHyast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attributeEPSS 1.6%CVE-2023-33965CRITICALBrook's tproxy server is vulnerable to a drive-by command injection.EPSS 1.6%CVE-2024-53688HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 aEPSS 1.6%CVE-2026-58147CRITICALAuthorized remote code execution via password change functionality in T-Mobile 5G Box IDU routersEPSS 1.6%CVE-2024-9166CRITICALOS Command Injection in Atelmo Atemio AM 520 HD Full HD Satellite ReceiverEPSS 1.6%CVE-2022-40719HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routerEPSS 1.6%CVE-2022-37880HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%