This is the second in a series of demos I am creating about Remote Command Injection vulnerabilities for my paper on them.
This demos POST injections via simply tampering with the parameters/form input and shows the execution of several shell commands on the vulnerable server.
Check out our whitepaper on this HERE: http://insecurety.net/papers/web-apps...
This demo used Mutillidae.