Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementHard
A security analyst is investigating a potential compromise on a web server. The server logs show repeated attempts to execute commands through an input field on a public-facing web application. This indicates a vulnerability that allows an attacker to inject and run malicious code. What type of vulnerability does this scenario describe?
- ABroken Authentication
- BSQL Injection
- CCommand Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: C. Command Injection
Command Injection (or OS Command Injection) occurs when an attacker can inject and execute arbitrary operating system commands through a vulnerable application. The scenario specifically mentions 'execute commands through an input field', which is the hallmark of command injection.
Why the other options are wrong
- A. Broken Authentication refers to flaws in session management or login processes, not command execution via input fields.
- B. SQL Injection targets a database by injecting malicious SQL queries, not operating system commands.
- D. XSS involves injecting client-side scripts into web pages viewed by other users, not server-side commands.
Command Injection
A type of web vulnerability that allows an attacker to execute arbitrary operating system commands on the host server through a vulnerable application input.
- Occurs when an application passes unsanitized user input to a system shell.
- Can lead to full system compromise.
- Mitigated by input validation and using safer APIs.
Memory trick: XSS scripts, SQL queries, Command runs, Auth breaks.