Weaknesses of type CWE-78

4,616 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2021-28812HIGHCommand Injection Vulnerability in Video StationEPSS 1.6%CVE-2022-22684HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in SynEPSS 1.6%CVE-2025-46645MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 1.6%CVE-2026-78327CRITICALAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network SecuritEPSS 1.6%CVE-2026-71171HIGHDell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS ComEPSS 1.6%CVE-2024-40893MEDIUMFirewalla BTLE Authenticated Command InjectionEPSS 1.6%CVE-2026-14959CRITICALOS Command Injection in IBM Aspera FaspexEPSS 1.6%CVE-2026-20759HIGHOS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a loggedEPSS 1.6%CVE-2022-26670HIGHD-Link DIR-878 - Command InjectionEPSS 1.5%CVE-2025-54418CRITICALCodeIgniter4's ImageMagick Handler has Command Injection VulnerabilityEPSS 1.5%CVE-2022-48580HIGHA command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled EPSS 1.5%CVE-2025-5243CRITICALArbitrary File Upload in SMG Software's Information PortalEPSS 1.5%CVE-2025-68109CRITICALChurchCRM vulnerable to RCE with database restore functionalityEPSS 1.5%CVE-2024-39351HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP conEPSS 1.5%CVE-2022-25908HIGHAll versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-inputEPSS 1.5%CVE-2025-14500CRITICALIceWarp14 X-File-Operation Command Injection Remote Code Execution VulnerabilityEPSS 1.5%CVE-2024-47919CRITICALTiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.5%CVE-2026-24695HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-25109HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-24689HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%