Falhas do tipo CWE-78

4.603 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2018-0099—A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, remote attacker to perEPSS 3.4%CVE-2026-4591MEDIUMkalcaddle kodbox fileThumb Endpoint app.php checkBin os command injectionEPSS 3.4%CVE-2025-34334HIGHAudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via TestFax.php & LPEEPSS 3.4%CVE-2026-55173HIGHAVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sinkEPSS 3.4%CVE-2025-34029CRITICALEdimax EW-7438RPn Mini OS Command Injection via syscmd.aspEPSS 3.4%CVE-2024-58287HIGHreNgine 2.2.0 Authenticated Command Injection via Scan Engine ConfigurationEPSS 3.4%CVE-2026-2701CRITICALRCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 3.4%CVE-2025-66644HIGHArray Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.EPSS 3.4%KEVCVE-2021-41280CRITICALOS command injection in Sharetribe GoEPSS 3.4%CVE-2023-53963CRITICALSOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command InjectionEPSS 3.4%CVE-2026-90847CRITICALEFM ipTIME C200E System Setup iux_set.cgi os command injectionEPSS 3.4%CVE-2023-38692CRITICALCommand injection vulnerability in module management function in CloudExplorer LiteEPSS 3.4%CVE-2026-4627HIGHD-Link DIR-825/DIR-825R NTP Service libdeuteron_modules.so handler_update_system_time os command injectionEPSS 3.4%CVE-2026-2686CRITICALSECCN Dingcheng G10 session_login.cgi qq os command injectionEPSS 3.4%CVE-2026-74233CRITICALZbtlink MQWrt infosrvd Command InjectionEPSS 3.4%CVE-2020-2000HIGHPAN-OS: OS command injection and memory corruption vulnerabilityEPSS 3.4%CVE-2024-7066MEDIUMF-logic DataCube3 HTTP POST Request config_time_sync.php os command injectionEPSS 3.4%CVE-2026-46339CRITICAL9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routesEPSS 3.4%CVE-2023-31128HIGHNextCloud Cookbook's pull-checks.yml workflow is vulnerable to OS Command InjectionEPSS 3.3%CVE-2022-38649CRITICALApache Airflow Pinot provider allowed Command InjectionEPSS 3.3%