Web Hack List

Top 10 winner

Blind SSTI

Two exploitation techniques for code injection and server-side template injection: Error-Based, which triggers errors whose messages reflect the injected code's output, and Boolean Error-Based Blind, which conditionally raises an error as an oracle. Payloads cover six languages and give an attacker output and fast confirmation from otherwise blind injections.

Record

Researcher
Vladislav Korchagin
Published by
GitHub
Format
Repository

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Vladislav Korchagin, first published at the original source. Preserved copies are kept so the citation survives its host.