Collected research
Room for Escape: Scribbling Outside the Lines of Template Security
Templates that untrusted users may edit break out of their sandboxes: SharePoint's safe-mode page parser is fooled by delayed data binding into parsing a user site page as a trusted application page, and Java engines such as FreeMarker, Velocity and Jinjava are escaped through objects left reachable in the template context. The result is remote code execution as an unprivileged CMS user.
Record
- Researcher
- Oleksandr Mirosh and Alvaro Muñoz
- Published by
- i.blackhat.com
- Format
- Whitepaper
- Topic
- Injection
In the archive
Related sources
- SharePoint and Pwn: Remote Code Execution Against SharePoint Server Abusing DataSet
- Room for Escape: Scribbling Outside the Lines of Template Security
- DEF CON Safe Mode - Alvaro Muñoz and Oleksandr Mirosh - Room For Escape Scribbling Outside The Lines
Tags
This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .