Ssti Methodology

服务端模板注入(SSTI)的检测、引擎识别和利用。当目标是Flask/Jinja2/Django/Twig/Mako/Pug应用、存在用户输入回显、参数名含template/name/message/greeting时使用。Phase 0/1即覆盖快速检测和引擎识别,无须单独skill。如只需快速检测定位可直接使用Phase 0/1,无需阅读完整利用部分

wgpsec 17aea3d 7 files · 24.3 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/exploit/web-method/ssti-methodology commit 17aea3d480

Frequently asked questions

npx skillmds@latest add wgpsec/ssti-methodology