Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-43068HIGH Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authEPSS 0.8%CVE-2024-28748HIGHifm: Reading function in Smart PLC allows command injections EPSS 0.8%CVE-2024-28750HIGHifm: Deleting function in Smart PLC allows command injectionsEPSS 0.8%CVE-2026-54088CRITICALFile Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)EPSS 0.8%CVE-2024-7699HIGHPhoenix Contact: OS command execution in MGUARD productsEPSS 0.8%CVE-2023-34213HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 0.8%CVE-2025-8654HIGHKenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-75600HIGHFreePBX: Authenticated API generatedocs Host Command InjectionEPSS 0.8%CVE-2022-39057HIGHChanging Information Technology Inc. RAVA certificate validation system - Command InjectionEPSS 0.8%CVE-2022-24441MEDIUMCode InjectionEPSS 0.8%CVE-2024-48861HIGHQHoraEPSS 0.8%CVE-2025-31692HIGHAI (Artificial Intelligence) - Critical - Remote Code Execution - SA-CONTRIB-2025-021EPSS 0.8%CVE-2023-34139HIGHA command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 PatEPSS 0.8%CVE-2026-12943CRITICALThis Power Hardware Management Console update is being released to addressEPSS 0.8%CVE-2023-42128HIGHMagnet Forensics AXIOM Command Injection Remote Code Execution VulnerabilityEPSS 0.8%CVE-2026-35906CRITICALAn undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute aEPSS 0.8%CVE-2026-27113MEDIUMLiquid Prompt arbitrary command injection via crafted Git branch names in gitstatusd backendEPSS 0.8%CVE-2026-44190HIGHAnsible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script settingEPSS 0.8%CVE-2022-27486MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5EPSS 0.8%CVE-2026-81548HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.8%