Weaknesses of type CWE-78

4,628 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-8665HIGHOS Command Injection in Rapid7 InsightConnect Translate PluginEPSS 1.2%CVE-2026-80138CRITICALClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath ParameterEPSS 1.2%CVE-2026-19978MEDIUMjiantao88 android-mcp-server Command Execution index.js child_process.exec os command injectionEPSS 1.2%CVE-2026-0855HIGHMerit LILIN|IP Camera - OS Command InjectionEPSS 1.2%CVE-2023-47220MEDIUMMedia Streaming add-onEPSS 1.2%CVE-2026-24506HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 1.2%CVE-2026-4802HIGHCockpit: cockpit: arbitrary command execution via crafted links in system logs uiEPSS 1.2%CVE-2023-26128HIGHAll versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sanEPSS 1.2%CVE-2012-10037CRITICALPhpTax pfilez Parameter Exec Remote Code InjectionEPSS 1.2%CVE-2023-50198HIGHD-Link G416 cfgsave Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-40030HIGHparseusbs < 1.9 Command Injection via Volume Path ArgumentEPSS 1.2%CVE-2019-1627MEDIUMCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-51217HIGHAn issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted cEPSS 1.2%CVE-2025-63705HIGHNPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.EPSS 1.2%CVE-2026-40032HIGHUAC < 3.3.0-rc1 Command Injection via Placeholder SubstitutionEPSS 1.2%CVE-2023-52311CRITICALCommand injection in _wget_downloadEPSS 1.2%CVE-2023-52310CRITICALCommand injection in get_online_pass_intervalEPSS 1.2%CVE-2023-52314CRITICALCommand injection in convert_shape_compareEPSS 1.2%CVE-2026-23816HIGHAuthenticated Command Injection found in admin AOS-CX CLI commandEPSS 1.2%CVE-2024-39686CRITICALfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen functionEPSS 1.2%