Falhas do tipo CWE-78

4.652 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-50362HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50365HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2024-50360HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.1%CVE-2022-43629MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43632MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43627MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43626MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43633MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43624MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2022-43631MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 1.1%CVE-2026-35582HIGHEmissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in ExecutrixEPSS 1.1%CVE-2024-38510HIGHA privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user wiEPSS 1.1%CVE-2024-50566HIGHA improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.EPSS 1.1%CVE-2026-32000MEDIUMOpenClaw < 2026.2.19 - Command Injection via Windows Shell Fallback in Lobster Tool ExecutionEPSS 1.1%CVE-2026-11739MEDIUMCommand injection vulnerability in some NETGEAR Nighthawk devicesEPSS 1.1%CVE-2026-11527HIGHConfig::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandleEPSS 1.1%CVE-2025-56803HIGHFigma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbEPSS 1.1%CVE-2026-16733MEDIUMbahmutov find-cypress-specs Branch index.js shell.exec os command injectionEPSS 1.1%CVE-2026-67434HIGHPHP_CodeSniffer gitblame report command injection via crafted filenameEPSS 1.1%CVE-2025-5459HIGHOS Command InjectionEPSS 1.1%