Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-25350HIGHAll versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization. EPSS 1.2%CVE-2022-21810HIGHAll versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization. EPSS 1.2%CVE-2021-43984CRITICALmySCADA myPROEPSS 1.2%CVE-2021-22657CRITICALmySCADA myPROEPSS 1.2%CVE-2021-23198CRITICALmySCADA myPROEPSS 1.2%CVE-2021-43981CRITICALmySCADA myPROEPSS 1.2%CVE-2024-37140HIGHDell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an aEPSS 1.2%CVE-2026-54501CRITICALBrowsertrix: Arbitrary Command Injection due to Improper Command Sanitization in Git URLs specified as Custom BehaviorsEPSS 1.2%CVE-2024-57014HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour" parameter in setScEPSS 1.2%CVE-2024-43655CRITICALAny authenticated users can execute OS commands as root using the <redacted>.sh CGI script.EPSS 1.2%CVE-2024-21898HIGHQTS, QuTS heroEPSS 1.2%CVE-2024-25002HIGHCommand Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.EPSS 1.2%CVE-2021-47851CRITICALMini Mouse 9.2.0 - Remote Code ExecutionEPSS 1.2%CVE-2023-39300HIGHQTSEPSS 1.2%CVE-2024-25626HIGHYocto Project Security Advisory - BitBake/ToasterEPSS 1.2%CVE-2024-54082HIGHhome 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS cEPSS 1.2%CVE-2024-45721HIGHhome 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration scEPSS 1.2%CVE-2025-60965CRITICALOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 1.2%CVE-2025-20294MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 1.2%CVE-2025-60964CRITICALOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 1.2%