PortSwigger Web Security Academy: server-side template injection in a code context, breaking out of a Tornado expression to reach command execution.
Basic Server-Side Template Injection (Code Context)


PortSwigger Web Security Academy: server-side template injection in a code context, breaking out of a Tornado expression to reach command execution.

PortSwigger Web Security Academy: forcing an error to reveal Handlebars on Node.js, then adapting a documented exploit to reach remote code execution.

PortSwigger Web Security Academy: identifying FreeMarker from a verbose error and reading its own documentation to reach remote code execution.

PortSwigger Web Security Academy: basic server-side template injection in an ERB message parameter, escalated to command execution.

PortSwigger Web Security Academy: blind OS command injection where the output is redirected to a file in the web root and retrieved through the image endpoint.