Weaknesses of type CWE-78

4,626 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-10273MEDIUMphp-censor Webhook Endpoint GitBuild.php os command injectionEPSS 1.4%CVE-2026-27938HIGHWPGraphQL Repo Vulnerable to Command Injection via Unsanitized GitHub Actions Expression in Release WorkflowEPSS 1.4%CVE-2024-11062HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11064HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11063HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2024-11065HIGHD-Link DSL6740C - OS Command InjectionEPSS 1.4%CVE-2022-32752HIGHIBM Security Directory Suite VA command executionEPSS 1.4%CVE-2020-8130—There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe cEPSS 1.4%CVE-2022-45899MEDIUMNokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metaEPSS 1.4%CVE-2009-20011CRITICALContentKeeper Web Appliance < 125.10 RCE via mimencodeEPSS 1.4%CVE-2022-48069HIGHTotolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.EPSS 1.4%CVE-2022-41395HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in EPSS 1.4%CVE-2022-41396HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain multiple command injection vulnerabilities in the function setIEPSS 1.4%CVE-2026-22221HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1EPSS 1.4%CVE-2024-57025MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" parameter in setWiFiSEPSS 1.4%CVE-2024-33434CRITICALAn issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows aEPSS 1.4%CVE-2024-57023MEDIUMTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" parameter in setWiFiSEPSS 1.4%CVE-2025-11148CRITICALAll versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool that is interacted withEPSS 1.4%CVE-2026-11526CRITICALGD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandleEPSS 1.4%CVE-2025-39240HIGHSome Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input validation. AttackerEPSS 1.4%