Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-25468HIGHAn issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of theEPSS 0.9%CVE-2023-53981HIGHPhotoShow 3.0 Remote Code Execution via Exiftran Path InjectionEPSS 0.9%CVE-2026-63586CRITICALUnauthenticated Remote Code Execution via Shell Injection in Web Management InterfaceEPSS 0.9%CVE-2024-35306HIGHOS Command injection in Ajax PHP files through HTTP RequestEPSS 0.9%CVE-2025-67264HIGHAn OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local atEPSS 0.9%CVE-2026-40288CRITICALPraisonAI: Critical RCE via `type: job` workflow YAMLEPSS 0.9%CVE-2026-73625HIGHGitPython before 3.1.54 Remote Code Execution via kwarg value smugglingEPSS 0.9%CVE-2026-23500CRITICALDolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configurationEPSS 0.9%CVE-2026-28507HIGHIdno: Remote Code Execution via Chained Import File Write and Template Path TraversalEPSS 0.9%CVE-2026-85426CRITICALMOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client NamesEPSS 0.9%CVE-2019-12091HIGHNetskope client command injections vulnerabilityEPSS 0.9%CVE-2025-60963HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.9%CVE-2026-22313CRITICALOS Commands Executed with Administrative Permissions in Radiflow iSAP Smart CollectorEPSS 0.9%CVE-2026-16843HIGHSome Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with vaEPSS 0.9%CVE-2026-21837HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIEPSS 0.9%CVE-2026-44604HIGHRpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell commandEPSS 0.9%CVE-2026-25130CRITICALCybersecurity AI vulnerable to command Injection through argument injection in find_file Agent toolEPSS 0.9%CVE-2026-7246HIGH[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"EPSS 0.9%CVE-2026-1459HIGHA post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG3625-T50B firmware versEPSS 0.9%CVE-2025-67172HIGHRiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.EPSS 0.9%