Weaknesses of type CWE-78

4,629 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-3781CRITICALOS Command Injection vulnerability in WBSAirbackEPSS 1.2%CVE-2024-34205HIGHTOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.EPSS 1.2%CVE-2026-41451HIGHUAC < 3.3.0 Command Injection via User Substitution in parse_artifact.shEPSS 1.2%CVE-2024-6333HIGHAuthenticated Remote Code Execution in Altalink, Versalink & WorkCentre ProductsEPSS 1.2%CVE-2023-40145HIGHWeintek cMT3000 HMI Web CGI OS Command InjectionEPSS 1.2%CVE-2022-29843MEDIUMWestern Digital My Cloud OS 5 devices Command Injection VulnerabilityEPSS 1.2%CVE-2026-35216CRITICALBudibase: Unauthenticated Remote Code Execution via Webhook Trigger and Bash Automation StepEPSS 1.2%CVE-2024-42741HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfgEPSS 1.2%CVE-2024-9200HIGHA post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG4005-B50A firmware versEPSS 1.2%CVE-2025-60957CRITICALOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 1.2%CVE-2026-34977CRITICALAperi'Solve Affected by Unauthenticated RCE via JPSeek Analyzer CommandEPSS 1.2%CVE-2026-0854HIGHMerit LILIN|NVR - OS Command InjectionEPSS 1.2%CVE-2022-21143HIGHAirspan Networks Mimosa OS Command InjectionEPSS 1.2%CVE-2021-38478CRITICALInHand Networks IR615 RouterEPSS 1.2%CVE-2021-38470CRITICALInHand Networks IR615 RouterEPSS 1.2%CVE-2026-13760HIGHOS Command Injection in aws-cdk-lib Docker BundlingEPSS 1.2%CVE-2026-22761MEDIUMDell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote acEPSS 1.2%CVE-2026-84675HIGHOS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable vEPSS 1.2%CVE-2025-61591HIGHCursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code ExecutionEPSS 1.2%CVE-2026-1460HIGHA post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EXEPSS 1.2%