Weaknesses of type CWE-78

4,640 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-43633MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2024-38510HIGHA privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user wiEPSS 1.1%CVE-2022-43632MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2024-50566HIGHA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.EPSS 1.1%CVE-2026-32000MEDIUMOpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool ExecutionEPSS 1.1%CVE-2026-11527HIGHConfig::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandleEPSS 1.1%CVE-2026-11739MEDIUMCommand injection vulnerability in some NETGEAR Nighthawk devicesEPSS 1.1%CVE-2025-56803HIGHFigma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbEPSS 1.1%CVE-2026-16733MEDIUMbahmutov find-cypress-specs Branch index.js shell.exec os command injectionEPSS 1.1%CVE-2025-3499CRITICALUnauthenticated execution of arbitrary commands in Radiflow iSAP Smart CollectorEPSS 1.1%CVE-2024-21833HIGHMultiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. TheEPSS 1.1%CVE-2026-67434HIGHPHP_CodeSniffer gitblame report command injection via crafted filenameEPSS 1.1%CVE-2025-5459HIGHOS Command InjectionEPSS 1.1%CVE-2024-46484CRITICALTRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testserv.cgi component.EPSS 1.1%CVE-2026-22897HIGHQuNetSwitchEPSS 1.1%CVE-2024-12009HIGHA post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and eEPSS 1.1%CVE-2024-11253HIGHA post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyxel VMG8825-T50K firmEPSS 1.1%CVE-2024-12010HIGHA post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.EPSS 1.1%CVE-2023-32548HIGHOS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attackEPSS 1.1%CVE-2022-48624HIGHclose_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.EPSS 1.1%