Falhas do tipo CWE-78

4.604 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-30368HIGHA10 Thunder ADC CsrRequestView Command Injection Remote Code Execution VulnerabilityEPSS 3.0%CVE-2026-27811HIGHRoxy-WI has a Command Injection via diff parameter in config comparison allows authenticated RCEEPSS 3.0%CVE-2023-27216HIGHAn issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page.EPSS 3.0%CVE-2022-36231CRITICALpdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.EPSS 3.0%CVE-2025-34113HIGHTiki Wiki CMS Authenticated Command Injection in Calendar ModuleEPSS 3.0%CVE-2018-17707—This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.EPSS 3.0%CVE-2026-25070CRITICALXikeStor SKS8310-8X PingTestSet Command InjectionEPSS 3.0%CVE-2026-8153CRITICALCommand injection in Dashboard Server interfaceEPSS 3.0%CVE-2026-45744CRITICALTermix has an OS Command Injection in File Manager resolvePath endpointEPSS 3.0%CVE-2026-81467CRITICALDell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command EPSS 3.0%CVE-2026-6942CRITICALradare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter BypassEPSS 3.0%CVE-2026-8051HIGHOS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges toEPSS 3.0%CVE-2026-27476CRITICALRustFly 2.0.0 Command Injection via UDP Remote ControlEPSS 3.0%CVE-2025-34161CRITICALCoolify Git Repository Field Command Injection in Project Deployment WorkflowEPSS 3.0%CVE-2024-5717HIGHLogsign Unified SecOps Platform Command Injection Remote Code Execution VulnerabilityEPSS 3.0%CVE-2026-28269MEDIUMKiteworks Core has an OS Command InjectionEPSS 3.0%CVE-2024-8077MEDIUMTOTOLINK AC1200 T8 setTracerouteCfg os command injectionEPSS 2.9%CVE-2026-86151CRITICALTenda CP3 Network Configuration Management system.c sub_2F77E8 os command injectionEPSS 2.9%CVE-2026-86149CRITICALTenda CP3 NetCheckPing.cpp os command injectionEPSS 2.9%CVE-2026-86148CRITICALTenda CP3 Kylin system.c SystemAsh os command injectionEPSS 2.9%