Restructure repository: Remove OWASP categorization, organize by vulnerability type

Co-authored-by: Stalin-143 <161853795+Stalin-143@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-01-04 19:01:04 +00:00
parent 274734e91a
commit ba72efbc5e
46 changed files with 341 additions and 323 deletions
+17
View File
@@ -0,0 +1,17 @@
# Command Injection
## Description
Command injection is a cyber attack that involves executing arbitrary commands on a host operating system. This vulnerability occurs when an application passes unsafe user-supplied data to a system shell.
## Common Attack Vectors
- System administration interfaces
- File upload functionality
- Network diagnostic tools (ping, traceroute)
- Backup/restore functions
- Any feature that executes system commands
## Testing Approach
Submit command separators and system commands in input fields to test if the application executes arbitrary commands.
## Payloads
See `command-injection-payloads.txt` for a comprehensive list of command injection payloads.