Web Hack List

Collected research

Serverside Template Injection

Server-Side Template Injection

Unsafely embedding user input in a server-side template engine lets an attacker run template syntax on the server, usually escalating to arbitrary file read and write and remote code execution. The paper gives a detect, identify and exploit methodology plus generic escapes for FreeMarker, Velocity, Smarty, Twig and Jade, with sandbox escapes and zerodays in Alfresco and XWiki.

Record

Document
Server-Side Template Injection
Researcher
James Kettle
Published by
PortSwigger Research
Date
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of James Kettle, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .