Falhas do tipo CWE-78

4.591 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-50789HIGHSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.phpEPSS 4.3%CVE-2022-45717CRITICALIP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUEPSS 4.3%CVE-2024-3193HIGHMailCleaner Admin Endpoints os command injectionEPSS 4.2%CVE-2019-17095HIGHBitdefender BOX 2 bootstrap download_image command injection vulnerabilityEPSS 4.2%CVE-2017-16608—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. AuthenticatiEPSS 4.2%CVE-2025-30004HIGHXorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command InjectionEPSS 4.2%CVE-2026-8112MEDIUM8421bit MiniClaw kernel.ts executeCognitivePulse os command injectionEPSS 4.2%CVE-2022-50795HIGHSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.phpEPSS 4.2%CVE-2023-37903CRITICALSandbox Escape in vm2EPSS 4.2%CVE-2025-11138MEDIUMmirweiye wenkucms common.php createPathOne os command injectionEPSS 4.2%CVE-2017-6714—A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to exEPSS 4.2%CVE-2026-56413CRITICALOS Command Injection in StoneFly Storage ConcentratorEPSS 4.2%CVE-2024-53584CRITICALOpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.EPSS 4.2%CVE-2021-20035MEDIUMImproper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary coEPSS 4.2%KEVCVE-2022-25168—Command injection in org.apache.hadoop.fs.FileUtil.unTarUsingTarEPSS 4.2%CVE-2023-26482CRITICALScope of workflow operations is not validated in nextcloud serverEPSS 4.2%CVE-2023-6309MEDIUMmoses-smt mosesdecoder trans_result.php os command injectionEPSS 4.2%CVE-2026-26213HIGHthingino-firmware api.cgi Unauthenticated Command Injection in Captive PortalEPSS 4.1%CVE-2026-5547MEDIUMTenda AC10 httpd formAddMacfilterRule os command injectionEPSS 4.1%CVE-2024-14005CRITICALNagios XI < 2024R1.2 Command Injection via Docker WizardEPSS 4.1%