Falhas do tipo CWE-78

4.603 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2019-1865HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 3.6%CVE-2025-9026MEDIUMD-Link DIR-860L Simple Service Discovery Protocol cgibin ssdpcgi_main os command injectionEPSS 3.6%CVE-2026-36356CRITICALThe GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthenticated OS command injecEPSS 3.6%CVE-2020-2037HIGHPAN-OS: OS command injection vulnerability in the management web interfaceEPSS 3.6%CVE-2026-50289HIGHsysteminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on LinuxEPSS 3.6%CVE-2023-7304CRITICALRuijie RG-UAC nmc_sync.php Command InjectionEPSS 3.6%CVE-2025-34115HIGHOP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpEPSS 3.6%CVE-2022-37718HIGHThe management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerabilEPSS 3.5%CVE-2023-25582HIGHTwo OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted networEPSS 3.5%CVE-2023-25583HIGHTwo OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted networEPSS 3.5%CVE-2025-11490MEDIUMwonderwhy-er DesktopCommanderMCP Absolute Path command-manager.ts extractBaseCommand os command injectionEPSS 3.5%CVE-2023-4221HIGHChamilo LMS Learning Path PPT2LP Command Injection VulnerabilityEPSS 3.5%CVE-2023-4222HIGHChamilo LMS Learning Path PPT2LP Command Injection VulnerabilityEPSS 3.5%CVE-2019-12690HIGHCisco Firepower Management Center Command Injection VulnerabilityEPSS 3.5%CVE-2019-1850HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 3.5%CVE-2021-21289HIGHCommand Injection Vulnerability in MechanizeEPSS 3.5%CVE-2026-76197CRITICALAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 3.5%CVE-2026-48362CRITICALColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 3.5%CVE-2026-76195CRITICALAdobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 3.5%CVE-2022-42493CRITICALSeveral OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted netwEPSS 3.5%