Weaknesses of type CWE-78

4,626 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-50919CRITICALTdarr 2.00.15 - Command InjectionEPSS 1.4%CVE-2023-0164HIGHOrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because tEPSS 1.4%CVE-2025-41270CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47900HIGHRCE on backup configuration passwordEPSS 1.4%CVE-2025-41275CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41274CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41276CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41269CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47901HIGHRCE on restore configuration passwordEPSS 1.4%CVE-2025-41272CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41277CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2022-40954MEDIUMApache Airflow Spark Provider RCE that bypass restrictions to read arbitrary filesEPSS 1.4%CVE-2025-62354CRITICALImproper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to executeEPSS 1.4%CVE-2026-48547HIGHKanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.ymlEPSS 1.4%CVE-2026-27613CRITICALCGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)EPSS 1.4%CVE-2023-27367HIGHNETGEAR RAX30 libcms_cli Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2022-50691CRITICALMiniDVBLinux 5.4 Remote Root Command Execution via commands.shEPSS 1.4%CVE-2020-24552MEDIUMAtop Technology 3G/4G LTE Cellular to Ethernet and Serial Secure Industrial Gateway - Command InjectionEPSS 1.4%CVE-2025-12489HIGHevernote-mcp-server openBrowser Command Injection Privilege Escalation VulnerabilityEPSS 1.4%CVE-2026-10273MEDIUMphp-censor Webhook Endpoint GitBuild.php os command injectionEPSS 1.4%