CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsMedium

An analyst reviewing web server logs finds a request to a system administration script containing the parameter value: '; cat /etc/shadow #'. The application passed this parameter directly into a shell command executed on the server. Which vulnerability does this best represent?

  1. ASQL injection
  2. BCross-site scripting
  3. CBuffer overflow
  4. DCommand injection
Show answer & explanation

Correct answer: D. Command injection

Command injection occurs when untrusted input is passed to a system shell and executed as an OS command, as shown by the semicolon used to chain an additional shell command onto the intended one. This differs from SQL injection, which targets database query syntax rather than the operating system shell.

Why the other options are wrong

  • A. Wrong: SQL injection targets database queries, not OS shell commands.
  • B. Wrong: XSS injects scripts executed in a victim's browser, not server-side shell commands.
  • C. Wrong: buffer overflow involves overflowing memory boundaries, not shell command chaining.

Command Injection

A vulnerability where an application passes untrusted user input directly to a system shell, allowing an attacker to execute arbitrary OS commands.

  • Often uses shell metacharacters like ; | & to chain commands
  • Mitigated by input validation and avoiding shell calls with user input
  • Can lead to full system compromise

Memory trick: A semicolon in the input is the attacker's command chain-link.

More Threats, Vulnerabilities, and Mitigations questions