Falhas do tipo CWE-78

4.646 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-24467HIGHPossible Command Injection in OpenText iManagerEPSS 1.1%CVE-2022-25926HIGHVersions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanEPSS 1.1%CVE-2025-9588CRITICALOS Command Injection in Iron Mountain's enVisionEPSS 1.1%CVE-2023-33839HIGHIBM Security Verify Governance command executionEPSS 1.1%CVE-2026-26279CRITICALFroxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command InjectionEPSS 1.1%CVE-2025-53376MEDIUMDokploy allows attackers to run arbitrary OS commands on the Dokploy host.EPSS 1.1%CVE-2022-25916HIGHVersions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scaEPSS 1.1%CVE-2024-36394CRITICALSysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.1%CVE-2025-63334CRITICALPocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php compoEPSS 1.1%CVE-2024-0166HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker couEPSS 1.1%CVE-2024-4301HIGHN-Reporter and N-Cloud from N-Partner - Os Command InjectionEPSS 1.1%CVE-2026-22100HIGHComnand injection in OCPP ReserveLogin messageEPSS 1.1%CVE-2026-76156CRITICALDatiphy Data Management Center - Improper Neutralization of Special Elements used in an OS CommandEPSS 1.1%CVE-2024-36061CRITICALEnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shEPSS 1.1%CVE-2024-8279HIGHA privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perfEPSS 1.1%CVE-2024-8278HIGHA privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perfEPSS 1.1%CVE-2024-20483HIGHCisco IOS XR PON Controller Command Injection VulnerabilitiesEPSS 1.1%CVE-2025-6225MEDIUMCommand injection in Kieback&Peter Neutrino-GLTEPSS 1.1%CVE-2026-72579HIGHNASA HyperCP - OS Command Injection via Malicious HTTP Response from Data ServerEPSS 1.1%CVE-2023-38317CRITICALAn issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing EPSS 1.1%