Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-67738HIGHsquid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache ManagerEPSS 0.4%CVE-2026-79761MEDIUMTermix: Command injection in SSH key deployment verificationEPSS 0.4%CVE-2026-34149LOWCoolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup JobsEPSS 0.4%CVE-2025-13686MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2025-13688MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2025-13687MEDIUMDataStage on Cloud Pak for Data is vulnerable to arbitrary code injection due to runtime environmentEPSS 0.4%CVE-2020-3417MEDIUMCisco IOS XE Software Arbitrary Code Execution VulnerabilityEPSS 0.4%CVE-2019-1732MEDIUMCisco NX-OS Software Remote Package Manager Command Injection VulnerabilityEPSS 0.4%CVE-2025-45378CRITICALDell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known password can break into EPSS 0.4%CVE-2026-81623MEDIUMIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.4%CVE-2026-45626MEDIUMArcane: OS Command Injection in Volume Browser ListDirectory via path query parameterEPSS 0.4%CVE-2026-1345HIGHSecurity Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.4%CVE-2026-45369HIGHpython-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication ProtocolEPSS 0.4%CVE-2022-33923MEDIUMDell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment. A locally authenticaEPSS 0.4%CVE-2025-24936CRITICALInsufficient Validation of Input in the URLEPSS 0.4%CVE-2024-55021HIGHWeintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded password in the FTP protocol.EPSS 0.4%CVE-2026-9279HIGHShell command injection in LogseqEPSS 0.3%CVE-2026-50227MEDIUMMQTT WebSocket Command Execution Vulnerability in NitroSenseEPSS 0.3%CVE-2023-28805MEDIUMZCC on Linux privilege escalationEPSS 0.3%CVE-2026-20350MEDIUMCisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection VulnerabilityEPSS 0.3%