Weaknesses of type CWE-78

4,624 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-33228HIGHNVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplyingEPSS 1.4%CVE-2021-34602HIGHBender Charge Controller: Long URL could lead to webserver crashEPSS 1.4%CVE-2026-3964MEDIUMOpenAkita Chat API Endpoint shell.py run os command injectionEPSS 1.4%CVE-2025-1229MEDIUMolajowon Loggrove page os command injectionEPSS 1.4%CVE-2023-28394HIGHBeekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of tEPSS 1.4%CVE-2026-45087CRITICALDalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server ModeEPSS 1.4%CVE-2023-38032HIGHASUS RT-AC86U - Command injection vulnerability - 2EPSS 1.4%CVE-2023-38033HIGHASUS RT-AC86U - Command injection vulnerability - 3EPSS 1.4%CVE-2023-39236HIGHASUS RT-AC86U - Command injection vulnerability - 4EPSS 1.4%CVE-2023-38031HIGHASUS RT-AC86U - Command injection vulnerability - 1EPSS 1.4%CVE-2023-39237HIGHASUS RT-AC86U - Command injection vulnerability - 5EPSS 1.4%CVE-2025-29040CRITICALAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%CVE-2022-50919CRITICALTdarr 2.00.15 - Command InjectionEPSS 1.4%CVE-2023-0118CRITICALForeman: arbitrary code execution through templatesEPSS 1.4%CVE-2025-29041CRITICALAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710cEPSS 1.4%CVE-2023-0164HIGHOrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because tEPSS 1.4%CVE-2025-41276CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47901HIGHRCE on restore configuration passwordEPSS 1.4%CVE-2025-47900HIGHRCE on backup configuration passwordEPSS 1.4%CVE-2025-41277CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%