us-15-Kettle-Server-Side-Template-Injection-RCE-For-The-Modern-Web-App-wp外文文献.pdfVIP

  • 52
  • 0
  • 约3.51万字
  • 约 20页
  • 2015-10-17 发布于江西
  • 举报

us-15-Kettle-Server-Side-Template-Injection-RCE-For-The-Modern-Web-App-wp外文文献.pdf

Server-Side Template Injection: RCE for the modern webapp James Kettle - james.kettle@ - @albinowax Abstract Template engines are widely used by web applications to present dynamic data via web pages and emails. Unsafely embedding user input in templates enables Server-Side Template Injection , a frequently critical vulnerability that is extremely easy to mistake for Cross-Site Scripting (XSS), or miss entirely . Unlike XSS, Template Injection can be used to directly attack web servers internals and often obtain Remote Code Execution (RCE), turning

文档评论(0)

1亿VIP精品文档

相关文档