Weaknesses of type CWE-78

4,603 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-1360HIGHCambium Networks cnMaestro OS Command InjectionEPSS 1.9%CVE-2026-34387MEDIUMFleet vulnerable to OS command injection via crafted software package metadata in uninstall scriptsEPSS 1.8%CVE-2021-20017—A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobodEPSS 1.8%CVE-2026-4157HIGHChargePoint Home Flex revssh Service Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2025-59157CRITICALCoolify has Git Repository RCEEPSS 1.8%CVE-2025-63414CRITICALA Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary comEPSS 1.8%CVE-2024-37066MEDIUMA command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to execute arbitrary coEPSS 1.8%CVE-2022-1884CRITICALRemote Command Execution in gogs/gogsEPSS 1.8%CVE-2025-44960HIGHRUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.EPSS 1.8%CVE-2022-3226HIGHAn OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older thanEPSS 1.8%CVE-2021-47816MEDIUMThecus N4800Eco Nas Server Control Panel - Command InjectionEPSS 1.8%CVE-2024-44341HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parametEPSS 1.8%CVE-2020-2508HIGHCommand Injection Vulnerability in QTS and QuTS heroEPSS 1.8%CVE-2024-12985MEDIUMOvertek OT-E801G passwd os command injectionEPSS 1.8%CVE-2021-41254HIGHPrivilege escalation to cluster admin on multi-tenant environmentsEPSS 1.8%CVE-2026-0759CRITICALKatana Network Development Starter Kit executeCommand Command Injection Remote Code Execution VulnerabilityEPSS 1.8%CVE-2024-43648CRITICALAuthenticated command injection via <redacted>.exe <redacted> parameterEPSS 1.8%CVE-2022-43184CRITICALD-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.EPSS 1.8%CVE-2019-1896HIGHCisco Integrated Management Controller CSR Generation Command Injection VulnerabilityEPSS 1.8%CVE-2019-5072HIGHAn exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Router AC1200 Smart DualEPSS 1.8%