Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-40587MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice EPSS 0.6%CVE-2026-34035HIGHCoolify: Host RCE via Log Drain secret/env command injectionEPSS 0.6%CVE-2026-34057HIGHCoolify: Authenticated Remote Code Execution via Command Injection in Database Import Container NameEPSS 0.6%CVE-2026-72862CRITICALDokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCEEPSS 0.6%CVE-2026-35073MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.6%CVE-2024-13087LOWQHoraEPSS 0.6%CVE-2026-35071HIGHDell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS EPSS 0.6%CVE-2026-39420MEDIUMMaxKB: Sandbox escape via LD_PRELOAD bypassEPSS 0.6%CVE-2024-14026LOWQTS, QuTS heroEPSS 0.6%CVE-2026-49813MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-54483MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-35074MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%CVE-2023-49692HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAEPSS 0.6%CVE-2025-4230HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability Through CLIEPSS 0.6%CVE-2025-0356HIGHNEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands vEPSS 0.6%CVE-2026-85660CRITICALcli-mcp-server 0.2.5 Command Allowlist Bypass via Shell SubstitutionEPSS 0.6%CVE-2025-0680CRITICALNew Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.EPSS 0.6%CVE-2026-45431HIGHCommand Injection Vulnerability in GX Earth ONT ModelsEPSS 0.6%CVE-2026-48778HIGHNotepad++: Arbitrary Code Execution via config.xml commandLineInterpreterEPSS 0.6%