Lab: Server-side template injection using documentation
This lab is vulnerable to server-side template injection. To solve the lab, identify the template engine and use the documentation to work out how to execute arbitrary code, then delete the morale.txt
file from Carlos's home directory.
You can log in to your own account using the following credentials:
content-manager:C0nt3ntM4n4g3r
Steps
Login to the website using the given credentials
Click on View details of any product
Click on Edit template button
Remove the .name from any template syntax
Click on Save and View the Product Details
We can see that the website is using FreeMarker Template engine
Now view the /cat/passwd file
We can see that the webserver is vulnerable to SSTI
Delete the morale.txt file
Congrats! You have solved the lab.
Last updated
Was this helpful?