Mining and Defense of 10 Command execution vulnerabilities in DVWA Series
The general defense method for command execution vulnerabilities usually uses two functions: EscapeShellCmd and EscapeShellArg, which are analyzed below.
The EscapeShellCmd () function can escape all characters in a string that may be hidden from Shell to execute another command, such as pipe characters (|), semicolons (;), redirection (>), and read from a file (