Weaknesses of type CWE-78

4,631 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-4855HIGH A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to exeEPSS 1.1%CVE-2024-2659HIGH A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to exeEPSS 1.1%CVE-2025-34129HIGHLILIN DVR RCE via Malicious FTP/NTP ConfigurationEPSS 1.1%CVE-2026-41900HIGHOpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution EnvironmentEPSS 1.1%CVE-2024-23690HIGHEOL Netgear FVS336v3 Telnet Configuration Backup Command InjectionEPSS 1.1%CVE-2023-44080—An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList cEPSS 1.1%CVE-2023-45025CRITICALQTS, QuTS hero, QuTScloudEPSS 1.1%CVE-2026-27208CRITICALapi-gateway-deploy Affected by Exploitable Command Injection via Unprivileged Root ExecutionEPSS 1.1%CVE-2026-79641HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 1.1%CVE-2023-22279CRITICALMAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancEPSS 1.1%CVE-2026-43003HIGHAn issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install froEPSS 1.1%CVE-2023-41289MEDIUMQcalAgentEPSS 1.1%CVE-2023-47560HIGHQuMagieEPSS 1.1%CVE-2023-31209HIGHCommand injection via active checks and REST APIEPSS 1.1%CVE-2024-11983HIGHBillion Electric router - OS Command InjectionEPSS 1.1%CVE-2024-46316HIGHDrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cEPSS 1.1%CVE-2020-36198MEDIUMCommand Injection Vulnerability in Malware RemoverEPSS 1.1%CVE-2023-39294MEDIUMQTS, QuTS heroEPSS 1.1%CVE-2026-48163HIGHMariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)EPSS 1.1%CVE-2023-53872CRITICALWp2Fac 1.0 OS Command Injection via send.php EndpointEPSS 1.1%