Falhas do tipo CWE-78
4.612 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-1244HIGHEmacs: shell injection vulnerability in gnu emacs via custom "man" uri schemeEPSS 2.6%CVE-2019-1864HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 2.6%CVE-2025-6897MEDIUMD-Link DI-7300G+ httpd_debug.asp os command injectionEPSS 2.6%CVE-2022-30310CRITICALFESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerabilityEPSS 2.6%CVE-2022-30311CRITICALFESTO: CECC-X-M1 and Servo Press Kit YJKP OS Command Injection vulnerabilityEPSS 2.6%CVE-2021-29083HIGHImproper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.EPSS 2.6%CVE-2020-37027CRITICALSickbeard 0.1 - Remote Command InjectionEPSS 2.6%CVE-2021-47728CRITICALSelea Targa IP Camera Remote Code Execution via UtilsEPSS 2.6%CVE-2026-8450CRITICALHTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()EPSS 2.6%CVE-2020-36867HIGHNagios XI < 5.7.3 Command Injection in Report PDF DownloadEPSS 2.6%CVE-2021-36287HIGHDell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticEPSS 2.6%CVE-2019-25243HIGHFaceSentry 6.4.8 Authenticated Remote Command Injection via Ping TestEPSS 2.6%CVE-2026-26832CRITICALnode-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() functEPSS 2.6%CVE-2025-50194HIGHChamilo: OS Command Injection in /main/cron/lang/check_parse_lang.phpEPSS 2.6%CVE-2026-65091HIGHNVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploitEPSS 2.6%CVE-2025-50193HIGHChamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database parameterEPSS 2.6%CVE-2026-9347MEDIUMEdimax EW-7438RPn webs formWizSurvey os command injectionEPSS 2.6%CVE-2022-24394HIGHAuthenticated Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 2.6%CVE-2026-5965CRITICALNewSoft|NewSoftOA - OS Command InjectionEPSS 2.6%CVE-2026-6349CRITICALHGiga|iSherlock - OS Command InjectionEPSS 2.6%