Weaknesses of type CWE-78

4,652 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-36922CRITICALOS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)EPSS 0.8%CVE-2026-16287HIGHRoot Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-updateEPSS 0.8%CVE-2026-8301HIGHOS Command Injection in TUBITAK BILGEM's Pardus-boot-repairEPSS 0.8%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2026-76714HIGHAuthenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.8%CVE-2023-34343HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2025-55055MEDIUMCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 0.8%CVE-2023-34334HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2025-29887HIGHQuRouter 2.5EPSS 0.8%CVE-2023-25759MEDIUMOS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to runEPSS 0.8%CVE-2024-0168HIGH Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potenEPSS 0.8%CVE-2025-7723HIGHAuthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.8%CVE-2024-0170HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could EPSS 0.8%CVE-2026-35160MEDIUMDell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command (EPSS 0.8%CVE-2020-1605HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.EPSS 0.8%CVE-2026-15427HIGHOS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800vEPSS 0.8%CVE-2024-1628HIGHOS command injection vulnerabilities in GE HealthCare ultrasound devicesEPSS 0.8%CVE-2026-85168HIGHn8n before 1.123.73 Remote Code Execution via Git NodeEPSS 0.8%CVE-2026-73623HIGHGitPython before 3.1.54 Remote Code Execution via --templateEPSS 0.8%CVE-2026-21267HIGHDreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.8%