Falhas do tipo CWE-78

4.629 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-31476HIGHMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilitiEPSS 1.5%CVE-2024-31477HIGHMultiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilitiEPSS 1.5%CVE-2025-59844HIGHArgument injection vulnerability in SonarQube Scan ActionEPSS 1.5%CVE-2020-26284HIGHHugo can execute a binary from the current directory on WindowsEPSS 1.5%CVE-2026-24697HIGHAn OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55EPSS 1.5%CVE-2026-24699HIGHAn OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 andEPSS 1.5%CVE-2022-27647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.9EPSS 1.5%CVE-2023-35723HIGHD-Link DIR-X3260 prog.cgi SOAPAction Command Injection Remote Code Execution VulnerabilityEPSS 1.5%CVE-2026-24698HIGHAn OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmwareEPSS 1.5%CVE-2024-43657CRITICALWhen uploading new firmware, a shell script inside a firmware file is executed during its processing. This can be used to craft a custom firmware file with a custom script with arbitrary code, which will then be executed on the charging station.EPSS 1.5%CVE-2023-42495CRITICAL Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.5%CVE-2023-47802HIGHA vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP blocEPSS 1.5%CVE-2024-48860CRITICALQHoraEPSS 1.5%CVE-2026-75121HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postEPSS 1.5%CVE-2026-75123HIGHPLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_smtp_test_postEPSS 1.5%CVE-2026-0830HIGHCommand Injection in Kiro GitLab Merge Request HelperEPSS 1.5%CVE-2024-38887CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 1.5%CVE-2026-22553CRITICALInSAT MasterSCADA BUK-TS OS Command InjectionEPSS 1.5%CVE-2026-92993MEDIUMDromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injectionEPSS 1.5%CVE-2024-51023HIGHD-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySeEPSS 1.5%