SSTI
Identifying SSTI
Identifying the Template Engine



PoCs - Questions

Exploiting SSTI - Jinja2
Information Disclosure


Local File Inclusion (LFI)

Remote Code Execution (RCE)

PoCs - Questions

Exploiting SSTI - Twig
Information Disclosure

Local File Inclusion (LFI)

Remote Code Execution (RCE)

Further Remarks
PoCs - Questions
SSTI Tools of the Trade
Tools of the Trade
Last updated