handbook/tools/3.Web-Hacking/4.Injection/OS-Commands/Notes/1.What-is-Os-Command-Injection.md
2024-08-31 01:07:22 +02:00

649 B

Overview

!Screenshot from 2022-12-02 12-37-32.png

  • Allows an attacker to execute commands on the web server
  • Used to compromise other parts of the hosting infrastructure via pivoting

Example Exploit:

stockreport.pl & echo
aiwefwlguh & 29
  • Useful Commands: !Screenshot from 2022-12-02 12-37-18.png