Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-29048HIGHA component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runEPSS 1.3%CVE-2025-47212MEDIUMQTS, QuTS heroEPSS 1.3%CVE-2026-48997HIGHe107: Command Injection via shell expansion in ImageMagick resize destination pathEPSS 1.3%CVE-2024-45885HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2022-25890HIGHAll versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization. EPSS 1.3%CVE-2024-45891HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2022-24431HIGHCommand InjectionEPSS 1.3%CVE-2026-0596CRITICALCommand Injection in mlflow/mlflowEPSS 1.3%CVE-2026-40029HIGHparseusbs < 1.9 Command Injection via Crafted LNK FilenameEPSS 1.3%CVE-2020-12149MEDIUMOS Command Injection - Management File UploadEPSS 1.3%CVE-2024-44678HIGHGigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commaEPSS 1.3%CVE-2023-42788HIGHAn improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiEPSS 1.3%CVE-2026-22223HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1EPSS 1.3%CVE-2023-33239HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 1.3%CVE-2022-43907HIGHIBM Security Guardium command executionEPSS 1.3%CVE-2023-3939CRITICALMultiple command injection in ZkTeco-based OEM devicesEPSS 1.3%CVE-2025-47856HIGHTwo improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoiEPSS 1.3%CVE-2023-23779MEDIUMMultiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb verEPSS 1.3%CVE-2024-6507HIGHDeep Lake Kaggle command injectionEPSS 1.3%CVE-2025-14204MEDIUMTykoDev cherry-studio-TykoFork OAuth Server Discovery oauth-authorization-server redirectToAuthorization os command injectionEPSS 1.3%