Command injection in ping command
Closed this issue · 1 comments
dorlafo commented
Vulnerability location : commands.cpp:348
Type of vulnerability : The input to the ping function is not sanitized, thus we can use ;
to chain command and execute a calculator.
Exploit : After connecting to the server, the client can simply type :
ping epfl.ch;gnomecalculator