Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-28704HIGHFurbo dog camera - Command InjectionEPSS 1.0%CVE-2025-3499CRITICALUnauthenticated execution of arbitrary commands in Radiflow iSAP Smart CollectorEPSS 1.0%CVE-2023-34974HIGHQTS, QuTS hero, QuTScloud, QVR, QESEPSS 1.0%CVE-2026-11417HIGHOS Command Injection in NodejsFunction Bundling in aws-cdk-libEPSS 1.0%CVE-2024-28125CRITICALFitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed tEPSS 1.0%CVE-2024-31976HIGHEnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity paraEPSS 1.0%CVE-2026-34935CRITICALPraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()EPSS 1.0%CVE-2023-20231HIGHA vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against EPSS 1.0%CVE-2025-60006MEDIUMJunos OS Evolved: OS command injection vulnerabilities fixedEPSS 1.0%CVE-2026-36827MEDIUMA command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helEPSS 1.0%CVE-2025-37163HIGHAuthenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLIEPSS 1.0%CVE-2022-25962HIGHAll versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. EPSS 1.0%CVE-2026-5709HIGHAWS Research and Engineering Studio (RES) FileBrowser Command InjectionEPSS 1.0%CVE-2026-5707HIGHCommand Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES)EPSS 1.0%CVE-2026-81537HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.0%CVE-2025-57639MEDIUMOS Command injection vulnerability in Tenda AC9 1.0 was discovered to contain a command injection vulnerability via the usb.samba.guest.userEPSS 1.0%CVE-2022-43758HIGHRancher: Command injection in Git packageEPSS 1.0%CVE-2025-57457HIGHAn OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS CommandEPSS 1.0%CVE-2020-8105CRITICALCommand Execution due to unsanitized inputEPSS 1.0%CVE-2023-1082HIGHWelotec: Command injection vulnerability in TK500v1 router seriesEPSS 1.0%