Falhas do tipo CWE-78

4.637 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-68459HIGHRG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. EPSS 1.4%CVE-2026-5619MEDIUMBraffolk mcp-summarization-functions summarize_command mcp-server.ts os command injectionEPSS 1.4%CVE-2026-0785HIGHALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2026-5621MEDIUMChrisChinchilla Vale-MCP HTTP index.ts os command injectionEPSS 1.4%CVE-2025-7451CRITICALHgiga|iSherlock - OS Command InjectionEPSS 1.4%CVE-2022-43536HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.4%CVE-2026-0787HIGHALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%CVE-2026-20305CRITICALCisco Identity Services Engine Command Injection VulnerabilityEPSS 1.4%CVE-2023-39297HIGHQTS, QuTS hero, QuTScloudEPSS 1.4%CVE-2026-0261MEDIUMPAN-OS: Authenticated Admin Command Injection VulnerabilityEPSS 1.4%CVE-2022-23611HIGHOS command injection in iTunesRPC-RemasteredEPSS 1.4%CVE-2012-10028HIGHNetwin SurgeFTP <= v23c8 Authenticated RCEEPSS 1.4%CVE-2026-80127HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 1.4%CVE-2026-57499CRITICALLiman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)EPSS 1.4%CVE-2026-24893HIGHopenITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro ExpansionEPSS 1.4%CVE-2026-28209HIGHFreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integrationEPSS 1.4%CVE-2026-6849HIGHOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.4%CVE-2026-1428HIGHWellChoose|Single Sign-On Portal System - OS Command InjectionEPSS 1.4%CVE-2025-37171HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.4%