Falhas do tipo CWE-78

4.665 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-88274HIGHGV-LPC2011/LPC2211 - Wireless SSID Command InjectionEPSS 0.7%CVE-2024-29167HIGHSVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commEPSS 0.7%CVE-2021-0219MEDIUMJunos OS: Command injection vulnerability in 'request system software' CLI commandEPSS 0.7%CVE-2026-66902CRITICALGoogle::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system callEPSS 0.7%CVE-2026-45777CRITICALOpen XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command InjectionEPSS 0.7%CVE-2023-32568HIGHAn issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM web application doeEPSS 0.7%CVE-2024-8881MEDIUMA post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and EPSS 0.7%CVE-2024-36103MEDIUMOS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent atEPSS 0.7%CVE-2024-20358MEDIUMA vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco FirepEPSS 0.7%CVE-2023-23694MEDIUM Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attackEPSS 0.7%CVE-2026-46624CRITICALTwenty: SQL Injection via the timeZone fieldEPSS 0.7%CVE-2022-26413HIGHA command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticatedEPSS 0.7%CVE-2026-58236MEDIUMOS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP PlatformEPSS 0.7%CVE-2025-52994MEDIUMgif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7EPSS 0.7%CVE-2026-39938CRITICALCacti: Unauthenticated RCE on Graph ImageEPSS 0.7%CVE-2025-43941HIGHDell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.7%CVE-2026-27602HIGHModoboa has an OS Command InjectionEPSS 0.7%CVE-2024-55904HIGHIBM DevOps Deploy / IBM UrbanCode Deploy command injectionEPSS 0.7%CVE-2026-48787HIGHgin-vue-admin vulnerable to RCEEPSS 0.7%CVE-2026-63298HIGHLXD arbitrary lxc.conf directive injection via NVIDIA instance configurationEPSS 0.7%