simple server site template injection scanner !
-
Updated
Jul 17, 2022 - Shell
simple server site template injection scanner !
Writeups for portswigger labs.
All associated materials and tasks for the training
CVE-2022-40634: FreeMarker Server-Side Template Injection in CrafterCMS
CVE-2023-49964: FreeMarker Server-Side Template Injection in Alfresco
CVE-2022-25813: FreeMarker Server-Side Template Injection in Apache OfBiz
MAL-001: FreeMarker Server-Side Template Injection in Liferay Portal
CVE-2022-24442: FreeMarker Server-Side Template Injection in JetBrains YouTrack
FastAPI app with Jinja2 SSTI vulnerability example to demonstrate security risks in web applications.
Express app with Pug templates demonstrating SSTI vulnerability and secure implementation for educational purposes.
CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS
CVE-2021-46361: FreeMarker Restriction Bypass in Magnolia CMS
MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS
MAGNOLIA-8348: FreeMarker Restriction Bypass 3 in Magnolia CMS
🎯 Server Side Template Injection Payloads
Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Websites Vulnerability Scanner
Add a description, image, and links to the server-side-template-injection topic page so that developers can more easily learn about it.
To associate your repository with the server-side-template-injection topic, visit your repo's landing page and select "manage topics."