PARAMETERS: Injection Location - Command argument enclosed in quotes Method - GET Sanitization - Reject (high), no single quotes Output - output shown, error status disclosed, command shown