Weaknesses of type CWE-78

4,622 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2021-34352HIGHCommand Injection Vulnerability in QVREPSS 1.5%CVE-2023-31198HIGHOS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenticated attacker with EPSS 1.5%CVE-2024-50374CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2024-50370CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.5%CVE-2023-28742HIGHBIG-IP iQuery mesh vulnerabilityEPSS 1.5%CVE-2022-27489HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, EPSS 1.5%CVE-2023-2091HIGHKylinSoft youker-assistant adjust_cpufreq_scaling_governer os command injectionEPSS 1.5%CVE-2024-27516CRITICALServer-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obEPSS 1.5%CVE-2026-25195HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 1.5%CVE-2021-34351CRITICALCommand Injection Vulnerability in QVREPSS 1.5%CVE-2021-34348CRITICALCommand Injection Vulnerability in QVREPSS 1.5%CVE-2021-38685CRITICALCommand Injection Vulnerability in VioStorEPSS 1.5%CVE-2026-23774HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 1.5%CVE-2025-59844HIGHArgument injection vulnerability in SonarQube Scan ActionEPSS 1.5%CVE-2024-31476HIGHMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilitiEPSS 1.5%CVE-2024-31477HIGHMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilitiEPSS 1.5%CVE-2020-26284HIGHHugo can execute a binary from the current directory on WindowsEPSS 1.5%CVE-2026-24697HIGHAn OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55EPSS 1.5%CVE-2026-24698HIGHAn OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmwareEPSS 1.5%CVE-2026-24699HIGHAn OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 andEPSS 1.5%