CAPEC Definitions

    CAPEC Definitions / CAPEC-108

    CAPEC-108: Command Line Execution through SQL Injection

    An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.

    Severity:Very High
    Possibility:Low

    Extended Description

    No Extended Description.

    Mitigations

    Disable MSSQL xp_cmdshell directive on the database

    Properly validate the data (syntactically and semantically) before writing it to the database.

    Do not implicitly trust the data stored in the database. Re-validate it prior to usage to make sure that it is safe to use in a given context (e.g. as a command line argument).

    Relationships with other CAPECs

    CAPEC-66: SQL Injection

    Prerequisites

    The application does not properly validate data before storing in the database

    Backend application implicitly trusts the data stored in the database

    Malicious data is used on the backend as a command line argument

    Related Weaknesses

    CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

    CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    CWE-20: Improper Input Validation

    CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    CWE-114: Process Control