- 52
- 0
- 约3.51万字
- 约 20页
- 2015-10-17 发布于江西
- 举报
Server-Side Template Injection:
RCE for the modern webapp
James Kettle - james.kettle@ - @albinowax
Abstract
Template engines are widely used by web applications to present dynamic data via web pages and emails. Unsafely
embedding user input in templates enables Server-Side Template Injection , a frequently critical vulnerability that is
extremely easy to mistake for Cross-Site Scripting (XSS), or miss entirely . Unlike XSS, Template Injection can be used to
directly attack web servers internals and often obtain Remote Code Execution (RCE), turning
您可能关注的文档
- SQL Server 2005&2008 Installation and Configuration Guide外文文献.pdf
- SQL Server 2005(账户)权限及安全设置外文文献.pdf
- SQL Server 2005安装指南外文文献.pdf
- SQL server 2005案例教程 第4章 视图和索引外文文献.pdf
- SQL Server 2005备份还原操作说明外文文献.doc
- SQL Server 2005高可用性之复制外文文献.doc
- MCSE(Server Infrastructure)培训课程外文文献.doc
- MCSE(Windows Server 2012)外文文献.doc
- SQL Server 2005讲义I外文文献.doc
- SQL Server 2005开发环境搭建教程外文文献.doc
- Microsoft Developing Microsoft SharePoint Server 2013 Advanced Solutions 70-489题库外文文献.pdf
- Microsoft Developing Microsoft SharePoint Server 2013 Core Solutions 70-488题库外文文献.pdf
- Microsoft Developing Microsoft SQL Server 2012 Databases 70-464题库外文文献.pdf
- Microsoft Enterprise Voice Online Services with Microsoft Lync Server 2013 70-337题库外文文献.pdf
- Microsoft Exam 70-433 MCTS SQL Server 2008考试指南外文文献.doc
- VC++与SQL_Server_2000连接外文文献.doc
- VisualSVN Server的配置和使用方法外文文献.doc
- VisualSVN Server外文文献.doc
- VisualSVN_Server使用外文文献.pdf
- VMware ESX Server 4 安装外文文献.docx
最近下载
- 打井机井施工方案.doc VIP
- 2025年中国特种设备检测研究院招聘面试题库附答案.doc VIP
- 2024年黑龙江省哈尔滨市中考数学试题卷(含答案解析).docx
- 2025年贵州省黔东南州中考文科综合试题卷(含答案解析).docx
- 2025年山东潍坊初中学业水平考试地理试卷真题(含答案详解).pdf VIP
- GBT 18482-2010 可逆式抽水蓄能机组启动试运行规程.pdf
- 2024-2025学年天津市和平区人教版五年级下册期中测试数学试卷【含答案】.pdf VIP
- 2026医疗影像AI诊断系统临床应用与商业化报告.docx
- 新产品开发流程管理全套文档.docx VIP
- 2025年中国特种设备检测研究院招聘面试预测题及答案.doc VIP
原创力文档

文档评论(0)