Weaknesses of type CWE-78

4,629 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-36529HIGHAn OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited,EPSS 1.2%CVE-2025-59518HIGHIn LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ EPSS 1.2%CVE-2024-57595CRITICALDLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attaEPSS 1.2%CVE-2026-44724HIGHsysteminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile nameEPSS 1.2%CVE-2022-3133HIGHOS Command Injection in jgraph/drawioEPSS 1.2%CVE-2026-97366MEDIUMjhen0409 react-native-debugger Open in Editor window.js openDevTools os command injectionEPSS 1.2%CVE-2024-34073HIGHCommand Injection in sagemaker-python-sdkEPSS 1.2%CVE-2024-14010HIGHTypora 1.7.4 OS Command Injection via Export PDF PreferencesEPSS 1.2%CVE-2024-54024HIGHAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolatEPSS 1.2%CVE-2022-47555CRITICALImproper Neutralization of Special Elements in Ormazabal productsEPSS 1.1%CVE-2026-33396CRITICALOneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on ProbeEPSS 1.1%CVE-2024-53286HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in SynEPSS 1.1%CVE-2021-26726HIGHRemote code execution in Valmet DNA before Collection 2021EPSS 1.1%CVE-2025-28138CRITICALThe TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg functEPSS 1.1%CVE-2021-47748CRITICALHasura GraphQL 1.3.3 - Remote Code ExecutionEPSS 1.1%CVE-2025-71336CRITICALFlowise - Unsandboxed Remote Code Execution via Custom MCPEPSS 1.1%CVE-2025-57516HIGHOS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary comEPSS 1.1%CVE-2022-40741CRITICALSOFTNEXT TECHNOLOGIES CORP. Mail SQR Expert - Command InjectionEPSS 1.1%CVE-2026-5485HIGHOS command injection in Amazon Athena ODBC driver on LinuxEPSS 1.1%CVE-2025-15389HIGHQNO Technology|VPN Firewall - OS Command InjectionEPSS 1.1%