Falhas do tipo CWE-78

4.652 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-41871MEDIUMSEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in thEPSS 1.1%CVE-2025-66279HIGHQTS, QuTS heroEPSS 1.1%CVE-2025-53472HIGHWRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilEPSS 1.1%CVE-2024-24890HIGHCommand injection in ioprobe of gala-gopherEPSS 1.1%CVE-2025-66273HIGHQTS, QuTS heroEPSS 1.1%CVE-2026-15068CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.1%CVE-2024-30645HIGHTenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter.EPSS 1.0%CVE-2026-77521CRITICALMaxKB: Prompt-injectable agent can lead to command executionEPSS 1.0%CVE-2026-88889HIGHRenovate before 44.14.7 Command Injection via distributionTypeEPSS 1.0%CVE-2023-34975MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2026-41553CRITICALRemote Code Execution in PDF Export ModuleEPSS 1.0%CVE-2025-1036HIGHCommand injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privilegEPSS 1.0%CVE-2025-34147CRITICALShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via SSIDEPSS 1.0%CVE-2025-3022CRITICALOS Command Injection vulnerability in e-management of e-solutionsEPSS 1.0%CVE-2025-63261HIGHAWStats 8.0 is vulnerable to Command Injection via the open functionEPSS 1.0%CVE-2026-22035HIGHGreenshot Vulnerable to OS Command Injection via ExternalCommand PluginEPSS 1.0%CVE-2023-3572CRITICALPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 1.0%CVE-2025-30479HIGHDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gainEPSS 1.0%CVE-2024-35519HIGHNetgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi vEPSS 1.0%CVE-2026-11341MEDIUMD-Link DWR-M920 formIMEISetup sub_412DA0 os command injectionEPSS 1.0%