Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-24816MEDIUMset_term_title command injection in ipythonEPSS 1.3%CVE-2025-64111CRITICALGogs's update .git/config file allows remote command executionEPSS 1.3%CVE-2011-3178HIGHopenbuildservice webui code injectionEPSS 1.3%CVE-2025-37170HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2023-35019HIGHIBM Security Verify Governance command executionEPSS 1.3%CVE-2024-42757CRITICALCommand injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat functionEPSS 1.3%CVE-2025-56124HIGHOS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute arbitrary commands viaEPSS 1.3%CVE-2025-50946MEDIUMOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.EPSS 1.3%CVE-2025-11005CRITICALTOTOLINK X6000R Unauthenticated Command Injection VulnerabilityEPSS 1.3%CVE-2026-62312HIGH9Router: Authenticated RCE via Unvalidated MCP Plugin ArgumentsEPSS 1.3%CVE-2026-44590CRITICALSherlock: Command Injection via pull_request_target in validate_modified_targets.ymlEPSS 1.3%CVE-2026-28292CRITICALsimple-git has blockUnsafeOperationsPlugin bypass via case-insensitive protocol.allow config key that enables RCEEPSS 1.3%CVE-2022-24390HIGHAuthenticated Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.3%CVE-2026-24788HIGHRaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be exeEPSS 1.3%CVE-2024-12829HIGHArista NG Firewall ExecManagerImpl Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-8663MEDIUMOS Command Injection in Rapid7 InsightConnect RPM PluginEPSS 1.3%CVE-2026-8659MEDIUMOS Command Injection in Rapid7 InsightConnect SQLmap PluginEPSS 1.3%CVE-2026-8658MEDIUMOS Command Injection in Rapid7 InsightConnect Tcpdump PluginEPSS 1.3%CVE-2026-8664MEDIUMOS Command Injection in Rapid7 InsightConnect Finger PluginEPSS 1.3%CVE-2026-0630HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0EPSS 1.3%