Falhas do tipo CWE-78
4.668 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-44072MEDIUMOS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management paEPSS 0.6%CVE-2021-32475—ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3EPSS 0.6%CVE-2026-45556CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`EPSS 0.6%CVE-2023-48428HIGHA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected productsEPSS 0.6%CVE-2023-3571HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.6%CVE-2026-71179HIGHDell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OEPSS 0.6%CVE-2025-49008CRITICALAtheos Improper Input Validation Vulnerability Enables RCE in Common.phpEPSS 0.6%CVE-2024-56497MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7EPSS 0.6%CVE-2023-27198MEDIUMPAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the exec service and inclEPSS 0.6%CVE-2026-33145MEDIUMxrdp: Authenticated RCE via unsanitized AlternateShell execution in xrdp-sesmanEPSS 0.6%CVE-2026-22718MEDIUMCommand injection vulnerabilityEPSS 0.6%CVE-2020-13712HIGHMGOS Command InjectionEPSS 0.6%CVE-2025-24378HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2026-27848CRITICALMissing neutralization in Linksys MR9600, Linksys MX4200EPSS 0.6%CVE-2023-25554HIGH
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS
Command Injection') vulnerability exists that allows aEPSS 0.6%CVE-2026-27849CRITICALMissing neutralization in Linksys MR9600, Linksys MX4200EPSS 0.6%CVE-2025-24379HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-43920MEDIUMGNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to executeEPSS 0.6%CVE-2026-72877CRITICALDokploy: Command Injection via dockerImage in buildRemoteDockerEPSS 0.6%CVE-2023-24422HIGHA sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackerEPSS 0.6%