Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-4033HIGHOS Command Injection in mlflow/mlflowEPSS 1.3%CVE-2022-45045HIGHMultiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.0000EPSS 1.3%CVE-2026-84830HIGHOS command injection in privileged configuration handlingEPSS 1.2%CVE-2024-47901CRITICALA vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All veEPSS 1.2%CVE-2026-23678HIGHBinardat 10G08-0800GSM Network Switch Traceroute CLI Command InjectionEPSS 1.2%CVE-2019-16790MEDIUMRemote Code Execution in Tiny File ManagerEPSS 1.2%CVE-2023-3573HIGHPHOENIX CONTACT: Command Injection in WP 6xxx Web panelsEPSS 1.2%CVE-2023-3974CRITICALOS Command Injection in jgraph/drawioEPSS 1.2%CVE-2026-18264HIGHNoMachine getstat Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-0740CRITICALEclipse Target Management <= 4.5.500 Command InjectionEPSS 1.2%CVE-2025-46272CRITICALPlanet Technology Network Products OS Command InjectionEPSS 1.2%CVE-2025-64444HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. EPSS 1.2%CVE-2023-27356MEDIUMNETGEAR RAX30 logCtrl Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2022-28811CRITICALPossible command injection in Car Park Server in Carlo Gavazzi UWP3.0EPSS 1.2%CVE-2022-47208HIGHThe “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticEPSS 1.2%CVE-2022-47911CRITICALCVE-2022-47911EPSS 1.2%CVE-2023-21413CRITICALRemote code execution vulnerability during the installation of ACAP applications on the Axis deviceEPSS 1.2%CVE-2022-43483CRITICALCVE-2022-43483EPSS 1.2%CVE-2023-28702HIGHASUS RT-AC86U - Command InjectionEPSS 1.2%CVE-2021-42081CRITICALAuthenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355EPSS 1.2%