Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-42978CRITICALAn issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a craftedEPSS 1.2%CVE-2024-2359CRITICALImproper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webuiEPSS 1.2%CVE-2021-42081CRITICALAuthenticated Remote Command Execution vulnerability in OSNEXUS QuantaStor before 6.0.0.355EPSS 1.2%CVE-2026-41876HIGHOS Command Injection in R-SOFT DMSEPSS 1.2%CVE-2026-14371HIGHThe Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to PowershelEPSS 1.2%CVE-2025-58062HIGHLSTM-Kirigaya's openmcp-client Vulnerable to RCE in MCP Authorization FlowEPSS 1.2%CVE-2023-23355MEDIUMQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances), QVREPSS 1.2%CVE-2025-57799HIGHStreamVault can perform remote command executionEPSS 1.2%CVE-2026-16763MEDIUMlocalstack serverless-localstack Configuration index.js os command injectionEPSS 1.2%CVE-2022-40176—A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), DEPSS 1.2%CVE-2022-2253CRITICALDistributed Data Systems WebHMI OS Command InjectionEPSS 1.2%CVE-2023-29412CRITICALCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remEPSS 1.2%CVE-2025-53100HIGHRestDB's Codehooks.io MCP Server Vulnerable to Command InjectionEPSS 1.2%CVE-2026-4620HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2026-4622HIGHOS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.EPSS 1.2%CVE-2024-8684HIGHOS Command Injection vulnerability in Revolution PiEPSS 1.2%CVE-2020-10603—WebAccess/NMS (versions prior to 3.0.2) does not properly sanitize user input and may allow an attacker to inject system commands remotely.EPSS 1.2%CVE-2025-5277CRITICALaws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the MCP client will run aEPSS 1.2%CVE-2025-8613HIGHVacron Camera ping Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2024-5672HIGHRed Lion Europe: mbNET.mini vulnerable to OS command injectionEPSS 1.2%