Weaknesses of type CWE-78

4,652 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-33238HIGHCommand-injection Vulnerability in Certificate ManagementEPSS 0.8%CVE-2026-14958CRITICALOS command injection in IBM Aspera FaspexEPSS 0.8%CVE-2019-16639CRITICALAn issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attaEPSS 0.8%CVE-2026-43685HIGHA Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating sEPSS 0.8%CVE-2023-46117CRITICALInadequate validation of retrieved subdomains may lead to a Remote Code Execution in reconFTWEPSS 0.8%CVE-2026-44194CRITICALOPNsense: RCE on user managmentEPSS 0.8%CVE-2026-46735HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS EPSS 0.8%CVE-2024-6091CRITICALShell Command Denylist Bypass in significant-gravitas/autogptEPSS 0.8%CVE-2023-25555MEDIUM A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists thaEPSS 0.8%CVE-2026-72885NONEDokploy: Authenticated Command Injection in Dokploy Dockerfile BuilderEPSS 0.8%CVE-2026-29607HIGHOpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper PersistenceEPSS 0.8%CVE-2018-0221—A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perforEPSS 0.8%CVE-2026-16022HIGHCommand Injection in @oblique/cliEPSS 0.8%CVE-2026-44191HIGHAnsible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settingsEPSS 0.8%CVE-2024-51005HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi.EPSS 0.8%CVE-2024-38882CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.8%CVE-2024-46486HIGHTP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.EPSS 0.8%CVE-2024-51252HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.8%CVE-2024-21906MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2023-28627HIGHOS Command Injection via GIT_PATH in pymedusaEPSS 0.8%