Falhas do tipo CWE-78

4.664 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-51248HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the moEPSS 0.8%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.8%CVE-2024-0167HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker coEPSS 0.8%CVE-2026-32003HIGHOpenClaw < 2026.2.22 - Remote Code Execution via SHELLOPTS/PS4 Environment Injection in system.runEPSS 0.8%CVE-2026-17625HIGHLangflow is affected by OS Command Injection in Model Context Protocol featuresEPSS 0.8%CVE-2026-55158CRITICALConflibot: Command injection via crafted pull request branch names under pull_request_targetEPSS 0.8%CVE-2025-58371CRITICALRoo Code is vulnerable to command injection via GitHub actions workflowEPSS 0.8%CVE-2021-21570MEDIUMDell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorEPSS 0.8%CVE-2025-2983MEDIUMLegrand SMS PowerView os command injectionEPSS 0.8%CVE-2026-57133HIGHPraisonAI utility shell safe-command wrapper allowlist bypass via shell chainingEPSS 0.8%CVE-2022-1362MEDIUMCambium Networks cnMaestro OS Command InjectionEPSS 0.8%CVE-2026-58652HIGHluci-app-travelmate - Arbitrary Command Execution via UCI Script ParameterEPSS 0.8%CVE-2022-45461HIGHThe Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users EPSS 0.8%CVE-2024-21903MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2022-22555MEDIUMDell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulneraEPSS 0.8%CVE-2022-43466MEDIUMOS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to executeEPSS 0.8%CVE-2011-10007HIGHFile::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted file nameEPSS 0.8%CVE-2026-25063HIGHgradle-completion has a Bash command injection issueEPSS 0.8%CVE-2026-32968CRITICALUnauthenticated RCE in com_mb24sysapiEPSS 0.8%CVE-2023-34254HIGHRemote inventory task command injection when using ssh command modeEPSS 0.8%