COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONLive MITRE record
CAPEC-108
Command Line Execution through SQL Injection
Abstraction
Detailed
Typical severity
Very High
Likelihood of attack
Low
Understand the attack
What is this attack pattern?
Execution flow
How does the attack proceed, step by step?
Explore
Probe for SQL Injection vulnerability
Exploit
Achieve arbitrary command execution through SQL Injection with the MSSQL_xp_cmdshell directive
Inject malicious data in the database
Trigger command line execution with injected arguments
Requirements
What does the attack require?
Prerequisites
Skills required
Resources required
Impact
What does a successful attack lead to?
Modify Data
Read Data
Unreliable Execution
Gain Privileges
Execute Unauthorized Commands
Defence
How is it prevented and mitigated?
1
2
3
Real world