High rating bypass of Command Injection in DVWA (V1.10)
First, you can see the filter array in high.php as shown below:
Here I think of two kinds of bypass, one can be found on the Internet, and the other is combined according to medium.php 's way of bypass.
The first kind:
Notice the third'| = >''of the array, where there is a space to the right of the vertical bar.
So we can construct "127.0.0.1 | whoami"
Replace the space on the right with the space on the left to bypass it, as shown below:
The second kind:
The &; & method is used in the medium.ph bypass, and the combination bypass is also tried in high. My combination is "127.0.0.1 | whoami". The result is as follows: