Falhas do tipo CWE-78
4.647 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-38318CRITICALAn issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the gateway FQDN entry in the configuration file, allowing attackers EPSS 1.1%CVE-2023-38317CRITICALAn issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the network interface name entry in the configuration file, allowing EPSS 1.1%CVE-2023-38323CRITICALAn issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attaEPSS 1.1%CVE-2024-10202HIGHWellchoose Administrative Management System - OS Command InjectionEPSS 1.1%CVE-2025-49813MEDIUMAn improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC veEPSS 1.1%CVE-2024-23812HIGHA vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application incorrectly neutralizes special elementEPSS 1.1%CVE-2023-32976MEDIUMContainer StationEPSS 1.1%CVE-2024-35304CRITICALSystem command injection through Netflow functionEPSS 1.1%CVE-2023-24958HIGHIBM TS7700 Management Interface command injectionEPSS 1.1%CVE-2025-44635CRITICALThere are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG2-1350W, NR1200W serEPSS 1.1%CVE-2026-22893HIGHQTS, QuTS heroEPSS 1.1%CVE-2025-30247CRITICALAn OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remotEPSS 1.1%CVE-2026-10279MEDIUMhiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionEPSS 1.1%CVE-2023-27985HIGHemacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is relatedEPSS 1.1%CVE-2025-9573HIGHCommand Injection in extension "TYPO3 Backup Plus" (ns_backup)EPSS 1.1%CVE-2026-59561HIGHSakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed tEPSS 1.1%CVE-2026-45018CRITICALChainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionEPSS 1.1%CVE-2026-56137HIGHRPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted EPSS 1.1%CVE-2025-66208HIGHConfiguration-Dependent RCE (OS Command Injection) in richdocumentscode proxyEPSS 1.1%CVE-2022-43390MEDIUMA command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated aEPSS 1.1%