Weaknesses of type CWE-78

4,647 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-22224HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could pEPSS 0.9%CVE-2025-41267HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2025-41266HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2026-28391CRITICALOpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist EnforcementEPSS 0.9%CVE-2025-41279HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2024-8360MEDIUMVisteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39935HIGHjc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificatEPSS 0.9%CVE-2025-41265HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2024-8358MEDIUMVisteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-37861HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2024-8359MEDIUMVisteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-18272MEDIUMKenwood DNR1007XR startUpdateProcess Command Injection VulnerabilityEPSS 0.9%CVE-2023-34980MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2024-22223HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious usEPSS 0.9%CVE-2026-72767HIGHn8n before 1.123.67 Remote Code Execution via Git nodeEPSS 0.9%CVE-2026-61434HIGHPraisonAI before 4.6.78 Allowlist Bypass via find -execEPSS 0.9%CVE-2025-24351HIGHA vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attaEPSS 0.9%CVE-2026-42846CRITICALClipBucket: Remote Play URL Command InjectionEPSS 0.9%CVE-2026-38615CRITICALDedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.EPSS 0.9%CVE-2026-23592HIGHInsecure File Handling allows Remote Code Execution in Backup FunctionalityEPSS 0.9%