Weaknesses of type CWE-78

4,618 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-24695HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2023-30764CRITICALOS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command mEPSS 1.5%CVE-2021-3059HIGHPAN-OS: OS Command Injection Vulnerability When Performing Dynamic UpdatesEPSS 1.5%CVE-2025-61045HIGHTOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgeEPSS 1.5%CVE-2023-48802CRITICALIn TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str EPSS 1.5%CVE-2026-21654HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 1.5%CVE-2026-53804HIGHOTRS Community Edition OS Command Injection via PGP ConfigurationEPSS 1.5%CVE-2026-84194HIGHLibreNMS 23.10.0 before 26.4.0 OS Command Injection via HostnameEPSS 1.5%CVE-2026-28287HIGHFreePBX: Authenticated Remote Code Execution via Recordings Module AJAX EndpointsEPSS 1.5%CVE-2026-6837HIGHA post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4EPSS 1.5%CVE-2026-6952HIGHA post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions EPSS 1.5%CVE-2024-49601HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 1.5%CVE-2024-24330CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the EPSS 1.5%CVE-2026-20742HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-20910HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-20902HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2026-21389HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2023-5037HIGHAuthenticated Command InjectionEPSS 1.5%CVE-2025-34055CRITICALAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command ExecutionEPSS 1.5%CVE-2025-66052HIGHCommand injection in Vivotek IP7137 camerasEPSS 1.5%