Weaknesses of type CWE-78

4,623 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-27991HIGHThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEXEPSS 1.5%CVE-2020-36910HIGHCayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP ParameterEPSS 1.5%CVE-2023-40069CRITICALOS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS cEPSS 1.5%CVE-2026-40527HIGHradare2 Command Injection via DWARF Parameter NamesEPSS 1.5%CVE-2026-81937HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2026-84071HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2025-49141HIGHHaxCMS-PHP Command Injection VulnerabilityEPSS 1.5%CVE-2021-34349HIGHCommand Injection Vulnerability in QVREPSS 1.5%CVE-2021-28811HIGHVulnerability in Roon ServerEPSS 1.5%CVE-2026-31177CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinEPSS 1.4%CVE-2026-31178CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxEPSS 1.4%CVE-2026-31181CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunSerEPSS 1.4%CVE-2026-6721CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 1.4%CVE-2020-7879HIGHipTIME C200 IP Camera command injection vulnerabilityEPSS 1.4%CVE-2026-27650HIGHOS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may EPSS 1.4%CVE-2025-8078HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series firmwaEPSS 1.4%CVE-2026-92580HIGHAVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRFEPSS 1.4%CVE-2026-93533MEDIUMspatie Scotty Doctor DoctorCommand.php checkRemoteTools os command injectionEPSS 1.4%CVE-2024-4582HIGHFaraday GM8181/GM828x NTP Service os command injectionEPSS 1.4%CVE-2023-6437CRITICALAuthenticated RCEEPSS 1.4%