PortSwigger Web Security Academy: blind OS command injection where the output is redirected to a file in the web root and retrieved through the image endpoint.
Blind OS Command Injection with Output Redirection


PortSwigger Web Security Academy: blind OS command injection where the output is redirected to a file in the web root and retrieved through the image endpoint.

PortSwigger Web Security Academy: blind OS command injection detected with a time delay, injecting ping into the feedback email parameter.

PortSwigger Web Security Academy: OS command injection (simple case). Injecting whoami into an unsanitized stock-checker storeID parameter with Burp.