Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-1513HIGHA potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a speciaEPSS 0.6%CVE-2025-55048CRITICALMultiple CWE-78EPSS 0.6%CVE-2024-5399HIGHOpenfind Mail2000 - OS Command InjectionEPSS 0.6%CVE-2024-5403HIGHASKEY 5G NR Small Cell - Command InjectionEPSS 0.6%CVE-2024-27778HIGHAn improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 thrEPSS 0.6%CVE-2025-53680MEDIUMAn improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in FortinEPSS 0.6%CVE-2025-53870MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 througEPSS 0.6%CVE-2025-54072HIGHyt-dlp allows `--exec` command injection when using placeholder on WindowsEPSS 0.6%CVE-2023-5677MEDIUMBrandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input EPSS 0.6%CVE-2026-28797HIGHRAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" ComponentEPSS 0.6%CVE-2025-27613LOWGitk can create and truncate files in the user's home directoryEPSS 0.6%CVE-2026-27635HIGHManyfold vulnerable to OS command injection via ZIP filename in f3d renderEPSS 0.6%CVE-2025-0119MEDIUMCortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VMEPSS 0.6%CVE-2026-23820HIGHInconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLIEPSS 0.6%CVE-2025-64755HIGH@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File WritesEPSS 0.6%CVE-2026-16672HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2026-55249MEDIUM@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template StringEPSS 0.6%CVE-2022-27482HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.EPSS 0.6%CVE-2024-31478MEDIUMMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful expEPSS 0.6%CVE-2024-49281MEDIUMWordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.5%