Remote Code Execution from {SSTI} in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - 32nd USENIX Security Symposium (USENIX …, 2023 - usenix.org
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

Remote code execution from SSTI in the sandbox: automatically detecting and exploiting template escape bugs

Y Zhao, Y Zhang, M Yang - … of the 32nd USENIX Conference on Security …, 2023 - dl.acm.org
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

[PDF][PDF] Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - yuanxzhang.github.io
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

[PDF][PDF] Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - usenix.org
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

[PDF][PDF] Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - m.ezisraelc.com
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

[PDF][PDF] Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - m.ezisraelc.com
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …

[PDF][PDF] Remote Code Execution from SSTI in the Sandbox: Automatically Detecting and Exploiting Template Escape Bugs

Y Zhao, Y Zhang, M Yang - yuanxzhang.github.io
Template engines are widely used in web applications to ease the development of user
interfaces. The powerful capabilities provided by the template engines can be abused by …