Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-28279HIGH`osctrl-admin` Vulnerable to OS Command Injection via Environment ConfigurationEPSS 1.3%CVE-2023-40480HIGHNETGEAR RAX30 DHCP Server Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-40479HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-49329HIGHAnomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating system commands. This aEPSS 1.3%CVE-2025-37172HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.3%CVE-2024-28048CRITICALOS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS cEPSS 1.3%CVE-2022-44201CRITICALD-Link DIR823G 1.02B05 is vulnerable to Commad Injection.EPSS 1.3%CVE-2026-26318HIGHsysteminformation has Command Injection via Unsanitized `locate` Output in `versions()`EPSS 1.3%CVE-2018-25118CRITICALGeoVision Command Injection RCE via /PictureCatch.cgiEPSS 1.3%CVE-2026-35018HIGHNetComm NF20MESH < R6B032 Authenticated RCE via OS Command InjectionEPSS 1.3%CVE-2021-34362HIGHCommand Injection Vulnerability in Media Streaming Add-onEPSS 1.3%CVE-2026-49959HIGHHermes WebUI < 0.51.311 RCE via Git Configuration InjectionEPSS 1.3%CVE-2023-3260HIGHThe Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parametEPSS 1.3%CVE-2025-54763HIGHFutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the EPSS 1.3%CVE-2025-53508HIGHMultiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executEPSS 1.3%CVE-2023-35722HIGHNETGEAR RAX30 UPnP Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-26039HIGHZoneMinder vulnerable to OS Command injection in daemonControl() APIEPSS 1.3%CVE-2024-22423HIGHyt-dlp `--exec` command injection when using `%q` in yt-dlp on WindowsEPSS 1.3%CVE-2025-66576HIGHRemote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)EPSS 1.3%CVE-2023-4033HIGHOS Command Injection in mlflow/mlflowEPSS 1.3%