101

  • execute system commands o the backend server.
  • if webapp uses user input to execute system command on the backend server and then return a response, we can inject a payload to subvert the intended command and execute our commands.