ended9월 2일· 1 sources

A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

Why it matters

TL;DR - What: In GOautodial's goAPIv2 agent API, thegoPhone request parameter is escaped for SQL (mysqli_real_escape_string ) and then concatenated into anexec() command string. Shell metacharacters s...

1
Sources
+0
24h
Growth
18d
Active

Sources

Related Issues