Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-30631CRITICALAn issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrarEPSS 0.7%CVE-2025-8473MEDIUMAlpine iLX-507 UPDM_wstpCBCUpdStart Command Injection VulnerabilityEPSS 0.7%CVE-2026-53545CRITICALTermix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionEPSS 0.7%CVE-2023-37249—Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.EPSS 0.7%CVE-2026-91100MEDIUMHP Linux Imaging and Printing (HPLIP) Software– Multiple VulnerabilitiesEPSS 0.7%CVE-2026-50112HIGHApache CloudStack: RCE and SSRF in direct download, metalink and NFS templatesEPSS 0.7%CVE-2025-3128CRITICALMitsubishi Electric Europe smartRTU OS Command InjectionEPSS 0.7%CVE-2026-48347HIGHAnimate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.7%CVE-2024-7728HIGHCAYIN Technology CMS - OS Command InjectionEPSS 0.7%CVE-2026-55410MEDIUMNocoBase backup restore schema name allows command injectionEPSS 0.7%CVE-2024-50809HIGHThe theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commandsEPSS 0.7%CVE-2022-48593HIGHA SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48588HIGHA SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controllEPSS 0.7%CVE-2026-56685HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.7%CVE-2025-68700HIGHRAGFlow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2020-36877CRITICALReQuest Serious Play F3 Media Server <= 7.0.3 code executionEPSS 0.7%CVE-2026-72733CRITICALDokploy: OS Command Injection via `databaseName` / `backupFile` in database restoreEPSS 0.7%CVE-2026-16865HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.7%CVE-2026-17347HIGHpgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitutionEPSS 0.7%CVE-2024-51251HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the baEPSS 0.7%