Weaknesses of type CWE-78

4,629 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-29640CRITICALAn issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameEPSS 1.2%CVE-2023-47566MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.2%CVE-2025-9174MEDIUMneurobin shc Filename shc.c make os command injectionEPSS 1.2%CVE-2024-23789CRITICALEnergy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attackeEPSS 1.2%CVE-2022-48616MEDIUMA Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackersEPSS 1.2%CVE-2026-73167HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2022-2251MEDIUMImproper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.EPSS 1.2%CVE-2026-73163HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2026-73176HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2026-73164HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2020-15272HIGHShell-injection in git-tag-annotation GitHub actionEPSS 1.2%CVE-2026-73165HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2023-41352HIGHChunghwa Telecom NOKIA G-040W-Q - Command InjectionEPSS 1.2%CVE-2025-9176MEDIUMneurobin shc Environment Variable shc.c make os command injectionEPSS 1.2%CVE-2026-45630CRITICALDokploy: Authenticated Remote Code Execution via Command Injection in updateTraefikConfig Echo StatementEPSS 1.2%CVE-2025-20055CRITICALOS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. An attacker who can aEPSS 1.2%CVE-2026-27957HIGHCoolify: Authenticated RCE via command injection in CA certificate management featureEPSS 1.2%CVE-2026-42307MEDIUMVim: OS Command Injection in netrwEPSS 1.2%CVE-2024-20295HIGHA vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform commaEPSS 1.2%CVE-2020-5282HIGHarbitrary shell execution in Nick Chan BotEPSS 1.2%