Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-2415HIGHCommand injection vulnerability in Movistar 4G routerEPSS 0.7%CVE-2025-41683HIGHWeidmueller: Root Command Injection via Unsanitized Input in event_mail_test EndpointEPSS 0.7%CVE-2025-41684HIGHWeidmueller: Root Command Injection via Unsanitized Input in tls_iotgen_setting EndpointEPSS 0.7%CVE-2026-82077HIGHPaperCut NG/MF: Remote Code Execution via Scan2FaxEPSS 0.7%CVE-2026-32034MEDIUMOpenClaw < 2026.2.21 - Insecure Control UI Authentication over Plaintext HTTPEPSS 0.7%CVE-2025-6193MEDIUMTrustyai-explainability: command injection via lmevaljob crEPSS 0.7%CVE-2024-0401HIGHASUS OVPN RCEEPSS 0.7%CVE-2025-64340MEDIUMFastMCP has a Command Injection vulnerability - Gemini CLIEPSS 0.7%CVE-2022-48594HIGHA SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2023-32622—Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privEPSS 0.7%CVE-2022-48589HIGHA SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48597HIGHA SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpEPSS 0.7%CVE-2022-48602HIGHA SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48600HIGHA SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and paEPSS 0.7%CVE-2022-48590HIGHA SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐contrEPSS 0.7%CVE-2022-48601HIGHA SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inEPSS 0.7%CVE-2022-48595HIGHA SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlleEPSS 0.7%CVE-2022-48586HIGHA SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and pEPSS 0.7%CVE-2022-48603HIGHA SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48585HIGHA SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled inpuEPSS 0.7%