Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-23777HIGHAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0EPSS 1.3%CVE-2026-81669HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.3%CVE-2025-62193CRITICALNOAA PMEL Live Access Server (LAS) PyFerret command injectionEPSS 1.3%CVE-2022-45145CRITICALegg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egEPSS 1.3%CVE-2024-3126HIGHCommand Injection in parisneo/lollms-webuiEPSS 1.3%CVE-2024-42057HIGHA command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series fEPSS 1.3%CVE-2026-48719HIGHWarp branch selector command injection via Git branch namesEPSS 1.3%CVE-2024-6917CRITICALRCE in Veribilim Software's Veribase Order ManagementEPSS 1.3%CVE-2023-37292CRITICALHGiga iSherlock - Command InjectionEPSS 1.3%CVE-2026-90770HIGHSpug through 3.4.0 Remote Code Execution via ping_checkEPSS 1.3%CVE-2025-48069MEDIUMejson2env has insufficient input sanitizationEPSS 1.3%CVE-2026-12104HIGHAuthenticated OS Command Injection in BondixEPSS 1.3%CVE-2023-22815MEDIUMPost-authentication remote command injection vulnerability on Western Digital My Cloud OS 5 devicesEPSS 1.3%CVE-2023-25313CRITICALOS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the viEPSS 1.3%CVE-2026-41315CRITICALmdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.3%CVE-2024-50393HIGHQTS, QuTS heroEPSS 1.3%CVE-2026-45629CRITICALDokploy: Authenticated Remote Code Execution via Command Injection in /listen-deployment WebSocket EndpointEPSS 1.3%CVE-2026-0786HIGHALGO 8180 IP Audio Alerter SCI Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-5416HIGHCommand Injection via name parameterEPSS 1.3%CVE-2023-24816MEDIUMset_term_title command injection in ipythonEPSS 1.3%