Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-30097MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.4%CVE-2026-13248HIGHAuthenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command InterfaceEPSS 0.4%CVE-2025-30096MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.4%CVE-2025-14754HIGHIBM Cloud Pak for Data is vulnerable to OS command injectionEPSS 0.4%CVE-2020-3173HIGHCisco UCS Manager Software Local Management CLI Command Injection VulnerabilityEPSS 0.4%CVE-2026-81539HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.4%CVE-2026-12161HIGHImproper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH enEPSS 0.4%CVE-2025-58370HIGHRoo Code: Potential Remote Code Execution via Bash Parameter Expansion and Indirect ReferenceEPSS 0.4%CVE-2022-35642MEDIUM"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScriptEPSS 0.4%CVE-2026-71451MEDIUM- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0EPSS 0.4%CVE-2019-12717MEDIUMCisco NX-OS Software Virtualization Manager Command Injection VulnerabilityEPSS 0.4%CVE-2026-20283MEDIUMCisco Identity Services Engine IPSec Open API Command Injection VulnerabilityEPSS 0.4%CVE-2026-78229MEDIUMImage Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affectEPSS 0.4%CVE-2024-51246HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.4%CVE-2024-48954MEDIUMAn issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to ReEPSS 0.4%CVE-2026-76561HIGHPki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint)EPSS 0.4%CVE-2026-39417MEDIUMMaxKB: RCE via MCP stdio command injection in workflow engineEPSS 0.4%CVE-2024-32123MEDIUMMultiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer EPSS 0.4%CVE-2025-55211MEDIUMFreePBX Post-Authenticated Command InjectionEPSS 0.4%CVE-2025-30099HIGHDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.4%