Weaknesses of type CWE-78

4,616 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-37882HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.6%CVE-2022-3183CRITICALDataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provideEPSS 1.6%CVE-2024-53899HIGHvirtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not EPSS 1.6%CVE-2024-36360CRITICALOS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote EPSS 1.6%CVE-2020-15121HIGHCommand injection in Radare2EPSS 1.6%CVE-2026-29058CRITICALAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.phpEPSS 1.6%CVE-2023-23692HIGH Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially EPSS 1.6%CVE-2025-32107HIGHOS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vEPSS 1.6%CVE-2022-37924HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.6%CVE-2026-72573HIGH4xmen pm2panel - Authenticated OS Command Injection via id Query ParameterEPSS 1.6%CVE-2018-25122HIGHNagios XI < 5.4.13 Component Download Page RCEEPSS 1.6%CVE-2024-58314HIGHAtcom 2.7.x.x Authenticated Command Injection via Web Configuration CGIEPSS 1.6%CVE-2022-48583HIGHA command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 1.6%CVE-2022-48584HIGHA command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐contEPSS 1.6%CVE-2022-48582HIGHA command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlleEPSS 1.6%CVE-2026-50206HIGHVPN Command Injection VulnerabilityEPSS 1.6%CVE-2026-45662HIGHDokploy: Command Injection via incomplete shell escaping in docker logout (registry deletion)EPSS 1.6%CVE-2026-25836MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5EPSS 1.6%CVE-2024-1367HIGHCommand Injection Vulnerability in Tenable Security CenterEPSS 1.6%CVE-2024-45882HIGHDrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainEPSS 1.6%