Weaknesses of type CWE-78

4,630 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-15389HIGHQNO Technology|VPN Firewall - OS Command InjectionEPSS 1.1%CVE-2022-43654HIGHNETGEAR CAX30S SSO Command Injection Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-20164MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 1.1%CVE-2023-20163MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 1.1%CVE-2023-6795MEDIUMPAN-OS: OS Command Injection Vulnerability in the Web InterfaceEPSS 1.1%CVE-2025-20617HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE aEPSS 1.1%CVE-2023-23373HIGHQUSBCam2EPSS 1.1%CVE-2023-41288HIGHVideo StationEPSS 1.1%CVE-2026-41450HIGHUAC < 3.3.0 Command Injection via command_collector.shEPSS 1.1%CVE-2025-20016HIGHOS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an aEPSS 1.1%CVE-2024-45698CRITICALD-Link WiFi router - OS Command InjectionEPSS 1.1%CVE-2026-3828HIGHSome Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficieEPSS 1.1%CVE-2024-25568HIGHOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OSEPSS 1.1%CVE-2021-32826MEDIUMRemote code execution in Proxyee-DownEPSS 1.1%CVE-2026-28207MEDIUMZen-C Vulnerable to Command Injection via Malicious Output FilenameEPSS 1.1%CVE-2026-74997HIGHIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code executionEPSS 1.1%CVE-2021-42796CRITICALAn issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticateEPSS 1.1%CVE-2018-15380HIGHCisco HyperFlex Software Command Injection VulnerabilityEPSS 1.1%CVE-2024-0815CRITICALCommand injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0EPSS 1.1%CVE-2025-10767LOWCosmodiumCS OnlyRAT Configuration File main.py remote_download os command injectionEPSS 1.1%