漏洞描述
Detected potential OS command injection on Windows targets by replacing query parameter values with command separator payloads and identifying successful command execution through output patterns from `dir`, `whoami`, `systeminfo`, or response time delays induced via `ping`.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
owasp.orghttps://owasp.org/www-community/attacks/Command_Injection↗cwe.mitre.orghttps://cwe.mitre.org/data/definitions/78.html↗capec.mitre.orghttps://capec.mitre.org/data/definitions/88.html↗cheatsheetseries.owasp.orghttps://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html↗