Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-22280HIGHMAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancEPSS 1.0%CVE-2022-42053HIGHTenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the PortMappingServer parEPSS 1.0%CVE-2025-25053HIGHOS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitraryEPSS 1.0%CVE-2021-3769HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 1.0%CVE-2025-28256CRITICALAn issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWlanIdx of the file /liEPSS 1.0%CVE-2026-44168HIGHMariaDB: wsrep SST unsafe parameter handling on the donor sideEPSS 1.0%CVE-2022-1359MEDIUMCambium Networks cnMaestro Path TraversalEPSS 1.0%CVE-2026-27565CRITICALRemote code execution via uploading a malicious IODD fileEPSS 1.0%CVE-2023-41281MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-41282MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2023-44304HIGH Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploEPSS 1.0%CVE-2023-41283MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2026-48554HIGHNagios Core / XI Authenticated RCE via Unfiltered NOTIFICATION-Family Macro SubstitutionEPSS 1.0%CVE-2026-48553HIGHNagios Core / XI Authenticated RCE via Custom-Variable Macro InjectionEPSS 1.0%CVE-2020-7804MEDIUMActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShelEPSS 1.0%CVE-2025-41427HIGHWRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command InjectEPSS 1.0%CVE-2025-27804MEDIUMOS Command Injection Vulnerability in eCharge Hardy Barth cPH2 / cPP2 charging stationsEPSS 1.0%CVE-2023-47563HIGHVideo StationEPSS 1.0%CVE-2024-51008HIGHNetgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerEPSS 1.0%CVE-2024-51009HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulneraEPSS 1.0%