Falhas do tipo CWE-78

4.626 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-48582HIGHA command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlleEPSS 1.6%CVE-2022-48583HIGHA command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 1.6%CVE-2026-50206HIGHVPN Command Injection VulnerabilityEPSS 1.6%CVE-2026-25836MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5EPSS 1.6%CVE-2024-45882HIGHDrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainEPSS 1.6%CVE-2024-1367HIGHCommand Injection Vulnerability in Tenable Security CenterEPSS 1.6%CVE-2022-22684HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in SynEPSS 1.6%CVE-2021-28812HIGHCommand Injection Vulnerability in Video StationEPSS 1.6%CVE-2025-46645MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 1.6%CVE-2026-78327CRITICALAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network SecuritEPSS 1.6%CVE-2024-40893MEDIUMFirewalla BTLE Authenticated Command InjectionEPSS 1.6%CVE-2026-14959CRITICALOS Command Injection in IBM Aspera FaspexEPSS 1.6%CVE-2026-71171HIGHDell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS ComEPSS 1.6%CVE-2026-20759HIGHOS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a loggedEPSS 1.6%CVE-2025-54418CRITICALCodeIgniter4's ImageMagick Handler has Command Injection VulnerabilityEPSS 1.5%CVE-2022-26670HIGHD-Link DIR-878 - Command InjectionEPSS 1.5%CVE-2022-48580HIGHA command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled EPSS 1.5%CVE-2025-5243CRITICALArbitrary File Upload in SMG Software's Information PortalEPSS 1.5%CVE-2025-68109CRITICALChurchCRM vulnerable to RCE with database restore functionalityEPSS 1.5%CVE-2024-39351HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP conEPSS 1.5%