Can you elaborate on "pipe injection"? I can't find references to the term after brief searching, and I'm curious.
|adduser ...
or change the password, or so on to get a root shell or account.This has actually come back into style in certain places again, because so many devices are just linux boxes with busybox utils on constrained systems (think home routers for example a lot of those just display the output from various linux commands in their firewall stuff). But programmers don't always think about "what if someone is going to try and do pipe on this..." and you end up with a pipe injection.
It also can be used for privilege escalation if you have a lot of custom setuid stuff available for your sysadmins and someone manages to get a local account. (unfortunately more common than one would hope).