Falhas do tipo CWE-78

4.647 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-5023MEDIUMDeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injectionEPSS 1.1%CVE-2025-13942CRITICALA command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remoEPSS 1.1%CVE-2022-1410HIGHRemote Code Execution in Device42 ApplianceManager consoleEPSS 1.1%CVE-2019-1878HIGHCisco TelePresence Endpoint Command Shell Injection VulnerabilityEPSS 1.1%CVE-2022-25853HIGHAll versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitizaEPSS 1.1%CVE-2025-60017HIGHUnitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parEPSS 1.1%CVE-2024-51450CRITICALIBM Security Verify Directory Command ExecutionEPSS 1.1%CVE-2022-42279HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.1%CVE-2022-48472CRITICALA Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected productEPSS 1.1%CVE-2023-34979MEDIUMQTS, QuTS heroEPSS 1.1%CVE-2023-39302MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.1%CVE-2025-31104HIGHA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiADC 7.6.0 througEPSS 1.1%CVE-2025-8693HIGHA post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(ABVY.6.3)C0 and earliEPSS 1.1%CVE-2024-48863HIGHLicense CenterEPSS 1.1%CVE-2024-50368HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50363HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50364HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50360HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50367HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50362HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%