Falhas do tipo CWE-78

4.662 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-51021HIGHNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gEPSS 0.8%CVE-2023-44092HIGHOS Command InjectionEPSS 0.8%CVE-2024-10035CRITICALCode Injection in BG-TEK's CoslatV3EPSS 0.8%CVE-2026-84694HIGHCoolify before 4.2.0 Remote Code Execution via Environment Variable KeyEPSS 0.8%CVE-2026-6281HIGHA potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the locEPSS 0.8%CVE-2023-36922CRITICALOS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)EPSS 0.8%CVE-2026-16287HIGHRoot Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-updateEPSS 0.8%CVE-2026-8301HIGHOS Command Injection in TUBITAK BILGEM's Pardus-boot-repairEPSS 0.8%CVE-2026-76714HIGHAuthenticated Remote Code Execution with Elevated Privileges Vulnerability in HPE Networking Analytics and Location Engine (ALE)EPSS 0.8%CVE-2026-73787HIGHAuthenticated Arbitrary File Write allows Remote Code Execution via CPPM Web InterfaceEPSS 0.8%CVE-2025-55055MEDIUMCWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 0.8%CVE-2023-34334HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2023-34343HIGHAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, whEPSS 0.8%CVE-2025-29887HIGHQuRouter 2.5EPSS 0.8%CVE-2023-25759MEDIUMOS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to runEPSS 0.8%CVE-2025-7723HIGHAuthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2EPSS 0.8%CVE-2026-35160MEDIUMDell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command (EPSS 0.8%CVE-2024-0170HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could EPSS 0.8%CVE-2024-0168HIGH Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potenEPSS 0.8%CVE-2020-1605HIGHJunos OS and Junos OS Evolved: A vulnerability in JDHCPD allows an attacker to send crafted IPv4 packets and arbitrarily execute commands on the target device.EPSS 0.8%