Weaknesses of type CWE-78

4,622 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-37878HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.5%CVE-2026-16488LOWQUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injectionEPSS 1.5%CVE-2023-3741—An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on theEPSS 1.5%CVE-2026-59681HIGHyast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD joinEPSS 1.5%CVE-2026-49481CRITICALUpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmdEPSS 1.5%CVE-2025-2733MEDIUMmannaandpoem OpenManus Prompt python_execute.py os command injectionEPSS 1.5%CVE-2024-43656CRITICALA backup can be manipulated and then restored to create arbitrary files inside the <redacted> directory. A CGI script can be added to the web directory this way, allowing for full remote code execution.EPSS 1.5%CVE-2023-28983HIGHJunos OS Evolved: Shell Injection vulnerability in the gNOI serverEPSS 1.5%CVE-2023-35961HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35962HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35959HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35963HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2026-9862CRITICALCore Privileged Access Manager (BoKS) autoregistration service command injection vulnerabilityEPSS 1.5%CVE-2023-35964HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2023-35960HIGHMultiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file canEPSS 1.5%CVE-2021-31799HIGHIn RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a EPSS 1.5%CVE-2026-0795HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-21191HIGHVersions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checEPSS 1.5%CVE-2022-40740HIGHRealtek GPON router - Command InjectionEPSS 1.5%CVE-2026-26280HIGHSysteminformation has a Command Injection via unsanitized interface parameter in wifi.js retry pathEPSS 1.5%