Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-35174HIGHLivebook Desktop's protocol handler can be exploited to execute arbitrary command on WindowsEPSS 1.0%CVE-2025-15388HIGHQNO Technology|VPN Firewall - OS Command InjectionEPSS 1.0%CVE-2023-34108HIGHManipulation of Internal Dovecot Variables in mailcow via crafted PasswordsEPSS 1.0%CVE-2025-59370HIGHA command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnerability to potentEPSS 1.0%CVE-2024-3104CRITICALRemote Code Execution in mintplex-labs/anything-llmEPSS 1.0%CVE-2026-24719MEDIUMQTS, QuTS heroEPSS 1.0%CVE-2026-34597HIGHCoolify: Authenticated Host RCEEPSS 1.0%CVE-2025-14213HIGHCato's Socket WebUI is vulnerable to OS Command InjectionEPSS 1.0%CVE-2025-59156CRITICALCoolify has Docker Compose Injection issueEPSS 1.0%CVE-2021-42538HIGHEmerson WirelessHART GatewayEPSS 1.0%CVE-2025-2071CRITICALOS Command Injection Vulnerability in FAST LTA Silent Brick WebUIEPSS 1.0%CVE-2026-25620HIGHArista Edge Threat Management NGFW Captive Portal Encrypted Password Command InjectionEPSS 1.0%CVE-2026-25622HIGHArista Edge Threat Management NGFW Captive Portal Custom Handler Command InjectionEPSS 1.0%CVE-2022-31232HIGHSmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker may potentially expEPSS 1.0%CVE-2025-25220HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M versions prior to V2.0.EPSS 1.0%CVE-2024-1180MEDIUMTP-Link Omada ER605 Access Control Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-54181HIGHIBM WebSphere Automation command injectionEPSS 1.0%CVE-2026-25157HIGHOpenClaw/Clawdbot has OS Command Injection via Project Root Path in sshNodeCommandEPSS 1.0%CVE-2021-35402CRITICALPROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip EPSS 1.0%CVE-2022-45026CRITICALAn issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM eEPSS 1.0%