SSTI: Server Side Template Injection | Remote Code Execution | Reverse Connection | TPLMAP

Published: 19 February 2022
on channel: PentestHint - The Tech Fellow
1,499
29

#SSTI #ServerSideTemplateInjection #RCE #pentesthint #chandanghodela

Join this channel to get access to perks:
   / @pentesthint  

Hello Guys,

Server-side template injection is a vulnerability where the attacker injects malicious input into a template to execute commands on the server-side. This vulnerability occurs when invalid user input is embedded into the template engine which can generally lead to remote code execution (RCE).

Imact of SSTI
The impact of server-side template injection vulnerabilities is generally critical, resulting in remote code execution by taking full control of the back-end server. Even without the code execution, the attacker may be able to read sensitive data on the server. There are also rare cases where an SSTI vulnerability is not critical, depending on the template engine.

References:
http://disse.cting.org/2016/08/02/201...

TPLMAP: https://github.com/epinna/tplmap

Social Media Links:
Twitter: https://twiter.com/chandanghodela
LinkedIn:   / chandan-singh-ghodela  
Instagram:   / chandan.ghodela  


On this page of the site you can watch the video online SSTI: Server Side Template Injection | Remote Code Execution | Reverse Connection | TPLMAP with a duration of hours minute second in good quality, which was uploaded by the user PentestHint - The Tech Fellow 19 February 2022, share the link with friends and acquaintances, this video has already been watched 1,499 times on youtube and it was liked by 29 viewers. Enjoy your viewing!