CAPEC Definitions

    CAPEC Definitions / CAPEC-15

    CAPEC-15: Command Delimiters

    An attack of this type exploits a programs' vulnerabilities that allows an attacker's commands to be concatenated onto a legitimate command with the intent of targeting other resources such as the file system or database. The system that uses a filter or denylist input validation, as opposed to allowlist validation is vulnerable to an attacker who predicts delimiters (or combinations of delimiters) not present in the filter or denylist. As with other injection attacks, the attacker uses the command delimiter payload as an entry point to tunnel through the application and activate additional attacks through SQL queries, shell commands, network scanning, and so on.

    Severity:High
    Possibility:High

    Extended Description

    No Extended Description.

    Mitigations

    Design: Perform allowlist validation against a positive specification for command length, type, and parameters.

    Design: Limit program privileges, so if commands circumvent program input validation or filter routines then commands do not running under a privileged account

    Implementation: Perform input validation for all remote content.

    Implementation: Use type conversions such as JDBC prepared statements.

    Relationships with other CAPECs

    CAPEC-137: Parameter Injection

    Prerequisites

    Software's input validation or filtering must not detect and block presence of additional malicious command.

    Related Weaknesses

    CWE-146: Improper Neutralization of Expression/Command Delimiters

    CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

    CWE-184: Incomplete List of Disallowed Inputs

    CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    CWE-185: Incorrect Regular Expression

    CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

    CWE-140: Improper Neutralization of Delimiters

    CWE-157: Failure to Sanitize Paired Delimiters

    CWE-138: Improper Neutralization of Special Elements

    CWE-154: Improper Neutralization of Variable Name Delimiters

    CWE-697: Incorrect Comparison