Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2021-4466HIGHIPCop <= 2.1.9 Authenticated RCEEPSS 0.5%CVE-2024-52961HIGHAn improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FoEPSS 0.5%CVE-2024-31843MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are pEPSS 0.5%CVE-2025-67164CRITICALAn authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arEPSS 0.5%CVE-2026-70425MEDIUMDell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain EPSS 0.5%CVE-2026-52831HIGHNuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCEEPSS 0.5%CVE-2024-6032HIGHTesla Model S Iris Modem ql_atfwd Command Injection Code Execution VulnerabilityEPSS 0.5%CVE-2026-58502HIGHgithubtoplanguages: Command Injection via Issue Title in Discord Notification WorkflowEPSS 0.5%CVE-2024-21773HIGHMultiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to executeEPSS 0.5%CVE-2026-73081HIGHActivepieces: Remote Code Execution via Command Injection in Code Step NameEPSS 0.5%CVE-2023-37937HIGHAn improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.EPSS 0.5%CVE-2026-45578HIGHWWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLEPSS 0.5%CVE-2025-0415CRITICALCommand Injection in NTP SettingEPSS 0.5%CVE-2023-6926HIGHImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Crestron AM-300EPSS 0.5%CVE-2026-54636CRITICALDokku: OS Command Injection via app.json managed CronEPSS 0.5%CVE-2025-11142HIGHThe VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code execution. This flaw can onlEPSS 0.5%CVE-2025-59051HIGHFreePBX Endpoint Manager command injection via Network Scanning featureEPSS 0.5%CVE-2025-24385HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2025-43885HIGHDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS EPSS 0.5%CVE-2025-9996MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause theEPSS 0.5%