Falhas do tipo CWE-78

4.623 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2022-44567CRITICALA command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalEPSS 1.7%CVE-2022-34447HIGH PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An authenticated remote atEPSS 1.7%CVE-2025-32002CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard diEPSS 1.7%CVE-2026-72580CRITICALduhow xiaoai-patch - OS Command Injection in /mute and /unmute EndpointsEPSS 1.7%CVE-2024-3196MEDIUMMailCleaner SOAP Service dumpConfiguration os command injectionEPSS 1.7%CVE-2022-3276HIGHPuppetlabs-mysql Command InjectionEPSS 1.7%CVE-2026-18482CRITICALCVE-2026-18482EPSS 1.7%CVE-2024-31473CRITICALThere is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code executiEPSS 1.7%CVE-2021-3058HIGHPAN-OS: OS Command Injection Vulnerability in Web Interface XML APIEPSS 1.6%CVE-2021-47903HIGHLiteSpeed Web Server Enterprise 5.4.11 - Command InjectionEPSS 1.6%CVE-2026-10144HIGHRsbuild < 2.0.9 Command Injection via openBrowser() URL HandlingEPSS 1.6%CVE-2024-42742HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRuleEPSS 1.6%CVE-2024-42738HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. AutheEPSS 1.6%CVE-2024-42743HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . AEPSS 1.6%CVE-2024-42744HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUserEPSS 1.6%CVE-2026-56379CRITICALImageMagick - Command Injection via SVG DecoderEPSS 1.6%CVE-2023-52026CRITICALTOTOlink EX1800T V9.1.0cu.2112_B20220316 was discovered to contain a remote command execution (RCE) vulnerability via the telnet_enabled parEPSS 1.6%CVE-2018-15722—The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man iEPSS 1.6%CVE-2023-6078HIGHOS Command Injection vulnerability affecting BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023EPSS 1.6%