Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2020-12774HIGHD-Link DSL-7740C - Command InjectionEPSS 0.4%CVE-2019-1883HIGHCisco Integrated Management Controller CLI Command Injection VulnerabilityEPSS 0.4%CVE-2024-27920HIGHUnsigned code template execution through workflows in projectdiscovery/nucleiEPSS 0.4%CVE-2026-75364MEDIUMComfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitiEPSS 0.4%CVE-2025-30241HIGHOS Command Injection in Web Interface in Multiple TP-Link Aginet DevicesEPSS 0.4%CVE-2026-18824HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-42924HIGHBIG-IP iControl SOAP vulnerabilityEPSS 0.4%CVE-2025-30076HIGHKoha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.EPSS 0.4%CVE-2022-47210HIGHThe default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, hoEPSS 0.4%CVE-2025-58059CRITICALValtimo scripting engine can be used to gain access to sensitive data or resourcesEPSS 0.4%CVE-2026-32010MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via sort --compress-program ParameterEPSS 0.4%CVE-2020-3457MEDIUMCisco FXOS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-15986MEDIUMCisco Unity Express Command Injection VulnerabilityEPSS 0.4%CVE-2023-28767HIGHThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX serieEPSS 0.4%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.4%CVE-2026-87741HIGHConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' ParameterEPSS 0.4%CVE-2025-63408MEDIUMLocal Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to EPSS 0.4%CVE-2025-27614HIGHGitk allows arbitrary command executionEPSS 0.4%CVE-2022-26868MEDIUMDell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potenEPSS 0.4%CVE-2025-50974MEDIUMThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorpEPSS 0.4%