Falhas do tipo CWE-78

4.622 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-23060CRITICALTOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDmzCfg fuEPSS 1.7%CVE-2025-5952MEDIUMZend.To NSSDropoff.php exec os command injectionEPSS 1.7%CVE-2025-6559CRITICALSapido Wireless Router - OS Command InjectionEPSS 1.7%CVE-2023-3767CRITICALOS command injection on EasyPHP Webserver EPSS 1.7%CVE-2023-35762CRITICALOS Command Injection in INEA ME RTUEPSS 1.7%CVE-2026-40499HIGHradare2 < 6.1.4 Command Injection via PDB Parser print_gvars()EPSS 1.7%CVE-2026-68861HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 1.7%CVE-2025-34099CRITICALVICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth PasswordEPSS 1.7%CVE-2026-49261CRITICALMariaDB server has unsafe parameter handling in `wsrep_notify_cmd`EPSS 1.7%CVE-2022-39951HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.EPSS 1.7%CVE-2024-43651CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 1.7%CVE-2026-40079HIGHCacti: Command Injection via escape_command() no-op in RRDtool executionEPSS 1.7%CVE-2024-8807CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-24899HIGHCommand injection in aops-zeusEPSS 1.7%CVE-2026-45391HIGHLocal privilege escalation in Cribl Edge for LinuxEPSS 1.7%CVE-2024-8806CRITICALCohesive Networks VNS3 Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0780HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0779HIGHALGO 8180 IP Audio Alerter Ping Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2026-0781HIGHALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution VulnerabilityEPSS 1.7%CVE-2024-31977HIGHAdtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters EPSS 1.7%