Falhas do tipo CWE-78

4.604 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2023-36547CRITICALA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%CVE-2023-36549HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%CVE-2023-36548CRITICALA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%CVE-2024-48632HIGHD-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAdEPSS 2.1%CVE-2026-65130HIGHNVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploitEPSS 2.1%CVE-2026-19628HIGHRemote Code ExecutionEPSS 2.1%CVE-2026-26189MEDIUMTrivy Action has a script injection via sourced env file in composite actionEPSS 2.1%CVE-2026-79408CRITICALAn OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.EPSS 2.1%CVE-2026-94490MEDIUMOctoPrint Command API system.py executeSystemCommand os command injectionEPSS 2.1%CVE-2024-43653CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 2.1%CVE-2024-43654CRITICALAuthenticated command injection in the <redacted> action leads to full remote code execution as root on the charging stationEPSS 2.1%CVE-2026-49869CRITICALKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`EPSS 2.1%KEVCVE-2026-33475CRITICALLangflow GitHub Actions Shell InjectionEPSS 2.1%CVE-2020-7825HIGHA vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An EPSS 2.1%CVE-2024-4299HIGHHGiga iSherlock - Command InjectionEPSS 2.1%CVE-2023-34985HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%CVE-2024-4298HIGHHGiga iSherlock - Command InjectionEPSS 2.1%CVE-2023-34989HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%CVE-2021-31838HIGHCommand injection through environment variable in MVISION EDREPSS 2.1%CVE-2023-34987HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.EPSS 2.1%