Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-45251CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%CVE-2025-6542CRITICALOS command injection in multiple parametersEPSS 1.0%CVE-2024-38512HIGHA privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform coEPSS 1.0%CVE-2024-38511HIGHA privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user EPSS 1.0%CVE-2025-24817HIGHAn OS Command Injection vulnerability in Nokia MantaRay NMEPSS 1.0%CVE-2023-26129HIGHAll versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwmEPSS 1.0%CVE-2025-54795HIGHClaude Code echo command allowed bypass of user approval prompt for command executionEPSS 1.0%CVE-2025-27797CRITICALOS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS commaEPSS 1.0%CVE-2024-55590HIGHMultiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet ForEPSS 1.0%CVE-2026-16812CRITICALVeloCloud Orchestrator OS Command InjectionEPSS 1.0%KEVCVE-2025-60738CRITICALAn issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attaEPSS 1.0%CVE-2024-52021HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulneEPSS 1.0%CVE-2024-52020HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnEPSS 1.0%CVE-2026-84838HIGHRpm: command injection in rpmuncompress via unescaped filenames passed to popen()EPSS 1.0%CVE-2024-43778HIGHOS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticaEPSS 1.0%CVE-2026-35519HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline InjectionEPSS 1.0%CVE-2026-40176HIGHComposer is vulnerable to Command Injection via Malicious Perforce RepositoryEPSS 1.0%CVE-2022-40847HIGHIn Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This EPSS 1.0%CVE-2024-20335MEDIUMA vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticEPSS 1.0%CVE-2023-44415MEDIUMD-Link Multiple Routers cli Command Injection Remote Code Execution VulnerabilityEPSS 1.0%