Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-38588HIGHArcher C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OEPSS 0.4%CVE-2026-45750CRITICALTermix Vulnerable to Arbitrary Command Execution in File ManagerEPSS 0.4%CVE-2022-36926HIGHLocal Privilege Escalation in Zoom Rooms for macOS ClientsEPSS 0.4%CVE-2025-20193MEDIUMA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attackerEPSS 0.4%CVE-2026-81698CRITICALopenssl_encrypt before 1.4.9 Shell Injection via info commandEPSS 0.4%CVE-2024-44759HIGHAn arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to dowEPSS 0.4%CVE-2026-13476HIGHIBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code ExecutionEPSS 0.4%CVE-2026-16673HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.4%CVE-2026-33319MEDIUMAVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell CommandEPSS 0.4%CVE-2019-1879MEDIUMCisco Integrated Management Controller CLI Command Injection VulnerabilityEPSS 0.4%CVE-2025-9974HIGHInsufficient Input Validation on WEBUI in Nokia ONT/Beacon productEPSS 0.4%CVE-2017-15108—spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with accesEPSS 0.4%CVE-2020-29499MEDIUMDell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally auEPSS 0.4%CVE-2026-45408CRITICALDokku: OS Command Injection via App Name in Git Pre-Receive HookEPSS 0.4%CVE-2025-67041HIGHLantronix EDS3000PS OS Command InjectionEPSS 0.4%CVE-2026-20206MEDIUMCisco ThousandEyes BrowserBot Command Injection VulnerabilityEPSS 0.4%CVE-2023-40253MEDIUMImproper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNEPSS 0.4%CVE-2026-72880CRITICALDokploy: Arbitrary File Write + Remote OS Command Injection via `certificatePath`EPSS 0.4%CVE-2025-67035HIGHLantronix EDS5000 OS Command InjectionEPSS 0.4%CVE-2020-12774HIGHD-Link DSL-7740C - Command InjectionEPSS 0.4%