Weaknesses of type CWE-78

4,623 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-27647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.5%CVE-2026-24697HIGHAn OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55EPSS 1.5%CVE-2026-24699HIGHAn OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 andEPSS 1.5%CVE-2024-43657CRITICALWhen uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.EPSS 1.5%CVE-2023-42495CRITICAL Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.5%CVE-2023-47802HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP blocEPSS 1.5%CVE-2024-48860CRITICALQHoraEPSS 1.5%CVE-2026-75123HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_smtp_test_postEPSS 1.5%CVE-2026-75121HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postEPSS 1.5%CVE-2024-38887CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 1.5%CVE-2026-0830HIGHCommand Injection in Kiro GitLab Merge Request HelperEPSS 1.5%CVE-2026-22553CRITICALInSAT MasterSCADA BUK-TS OS Command InjectionEPSS 1.5%CVE-2024-51023HIGHD-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySeEPSS 1.5%CVE-2026-92993MEDIUMDromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injectionEPSS 1.5%CVE-2023-28528HIGHIBM AIX command executionEPSS 1.5%CVE-2022-39224HIGHArbitrary shell execution when extracting or listing files contained in a malicious rpm.EPSS 1.5%CVE-2022-37898HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.5%CVE-2025-14287HIGHCommand Injection in mlflow/mlflowEPSS 1.5%CVE-2026-32649HIGHMilesight Cameras OS Command InjectionEPSS 1.5%CVE-2023-51450MEDIUMbaserCMS OS command injection vulnerability in InstallerEPSS 1.5%