Weaknesses of type CWE-78

4,644 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2021-4470CRITICALTG8 Firewall Unauthenticated RCE via runphpcmd.phpEPSS 1.0%CVE-2022-42289HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.0%CVE-2022-42290HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.0%CVE-2026-1723CRITICALTOTOLINK X6000R Unauthenticated Command Injection VulnerabilityEPSS 1.0%CVE-2024-22225HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attackEPSS 1.0%CVE-2026-41113HIGHsagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.EPSS 1.0%CVE-2021-31854HIGHCode injection vulnerability in McAfee AgentEPSS 1.0%CVE-2026-72556HIGHZoneMinder ZoneMinder - Remote Code ExecutionEPSS 1.0%CVE-2026-72551HIGHApioo Fusio - Remote Code ExecutionEPSS 1.0%CVE-2026-63732CRITICAL9router before 0.4.60 Remote Code Execution via default passwordEPSS 1.0%CVE-2025-64124HIGHNuvation Energy Multi-Stack Controller OS Command InjectionEPSS 1.0%CVE-2025-64120CRITICALNuvation Energy Multi-Stack Controller OS Command InjectionEPSS 1.0%CVE-2026-9863HIGHCore Privileged Access Manager (BoKS) upgrade tooling command injection vulnerabilityEPSS 1.0%CVE-2025-11787HIGHCommand injection vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 1.0%CVE-2026-59721HIGHHoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injectionEPSS 1.0%CVE-2026-32950HIGHSQLBot: RCE via SQL Injection in Excel Upload EndpointEPSS 1.0%CVE-2026-81349HIGHAzure HDInsight Ambari Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2026-87898CRITICALOS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.EPSS 1.0%CVE-2024-45252CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%CVE-2024-45251CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%