Falhas do tipo CWE-78

4.652 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-42290HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.0%CVE-2021-4470CRITICALTG8 Firewall Unauthenticated RCE via runphpcmd.phpEPSS 1.0%CVE-2022-42289HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.0%CVE-2026-1723CRITICALTOTOLINK X6000R Unauthenticated Command Injection VulnerabilityEPSS 1.0%CVE-2024-22225HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attackEPSS 1.0%CVE-2026-72551HIGHApioo Fusio - Remote Code ExecutionEPSS 1.0%CVE-2021-31854HIGHCode injection vulnerability in McAfee AgentEPSS 1.0%CVE-2026-72556HIGHZoneMinder ZoneMinder - Remote Code ExecutionEPSS 1.0%CVE-2026-41113HIGHsagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.EPSS 1.0%CVE-2026-63732CRITICAL9router before 0.4.60 Remote Code Execution via default passwordEPSS 1.0%CVE-2025-64124HIGHNuvation Energy Multi-Stack Controller OS Command InjectionEPSS 1.0%CVE-2025-11787HIGHCommand injection vulnerability in Circutor SGE-PLC1000/SGE-PLC50EPSS 1.0%CVE-2026-9863HIGHCore Privileged Access Manager (BoKS) upgrade tooling command injection vulnerabilityEPSS 1.0%CVE-2025-64120CRITICALNuvation Energy Multi-Stack Controller OS Command InjectionEPSS 1.0%CVE-2026-32950HIGHSQLBot: RCE via SQL Injection in Excel Upload EndpointEPSS 1.0%CVE-2026-59721HIGHHoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injectionEPSS 1.0%CVE-2026-81349HIGHAzure HDInsight Ambari Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2024-45252CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%CVE-2025-0676HIGHCommend Injection Leading to Privilege EscalationEPSS 1.0%CVE-2024-45251CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%