ended9월 2일· 1 sources
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2
Why it matters
TL;DR - What: In GOautodial's goAPIv2 agent API, thegoPhone request parameter is escaped for SQL (mysqli_real_escape_string ) and then concatenated into anexec() command string. Shell metacharacters s...
1
Sources
+0
24h
—
Growth
18d
Active