Web Hack List

Collected research

Room for Escape: Scribbling Outside the Lines of Template Security

Templates that untrusted users may edit break out of their sandboxes: SharePoint's safe-mode page parser is fooled by delayed data binding into parsing a user site page as a trusted application page, and Java engines such as FreeMarker, Velocity and Jinjava are escaped through objects left reachable in the template context. The result is remote code execution as an unprivileged CMS user.

Record

Researcher
Oleksandr Mirosh and Alvaro Muñoz
Published by
i.blackhat.com
Format
Whitepaper
Topic
Injection

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Oleksandr Mirosh and Alvaro Muñoz, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .