OSCE3 Practice Questions - OffSec Certified Expert 3 (OSCE3) Exam

Question Number 5


In a white-box web application assessment for OSWE, you find a Java application using Runtime.getRuntime().exec() with user input concatenated into the command string. What is the most effective exploitation approach?
✔ Correct Answer:
Use OS command injection with semicolons or pipes to chain commands