Weaknesses of type CWE-78

4,665 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2018-19639MEDIUMCode execution if run with command line switch -vEPSS 0.5%CVE-2026-16856HIGHIBM i is Affected By Multiple Vulnerabilities in Domain Name SystemEPSS 0.5%CVE-2026-84085HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-53455HIGHBlueprint Studio Git credential helper command injectionEPSS 0.5%CVE-2026-16844HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-14277MEDIUMIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.5%CVE-2026-16848HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-82804HIGHApache DolphinScheduler: Command Injection in the Alert Script PluginEPSS 0.5%CVE-2026-16842HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-17186CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2024-2742MEDIUMOS Command Injection in Planet IGS-4215-16T2SEPSS 0.5%CVE-2025-46422HIGHDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2023-27999HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allowEPSS 0.5%CVE-2025-46423HIGHDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2025-20161MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2023-26210HIGHMultiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability inEPSS 0.5%CVE-2026-62943HIGHbtrbk: SSH Command Filter Bypass in ssh_filter_btrbk.shEPSS 0.5%CVE-2025-67034HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.5%CVE-2023-20175HIGHA vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on theEPSS 0.5%CVE-2024-24426HIGHReachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackeEPSS 0.5%