Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Research_Successful_Errors — Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming languages and integration into SSTImap. | Kitploit
Tools/GitHubGitHub/vladko312/research_successful_errors
Vulnerability AnalysisCode AnalysisWeb Application ExploitationFuzzingCTFPenetration TestingPapers & ResearchLearning & EducationPayload Development
GitHubvladko312/research_successful_errors

Research_Successful_Errors

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming languages and integration into SSTImap.

View Repository
12113137 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Successful Errors: New Code Injection and SSTI Techniques

Report version Last modified

[!NOTE] This is the second version of the whitepaper based on the results I presented before releasing SSTImap version 1.3.1. Further improvements would be adapted for this format as version 1.2 of the research at a later date.

  • Payloads
  • Printable whitepaper
  • Slides

Some categories of vulnerabilities might at first glance appear well-known and somewhat obvious. It might seem that all possible techniques for those vulnerabilities are known, so only payloads for unusual cases might be discovered. Server-Side Template Injection (SSTI) and Code Injection are often considered as those well-known categories.

Sometimes, new techniques with self-explaining names are encountered for those vulnerabilities. Many researchers might consider those techniques well-known as well or even remember using them, but in reality, the technique might only exist as a commonly understood name with no research, descriptions or universal payloads. It might be mentioned a couple of times alongside payloads for very specific cases, but it would not be tested for and the real potential of that technique might stay undiscovered for years.

This research introduces two such techniques for Code Injection and SSTI: Error-Based and Boolean Error-Based Blind. I will provide payloads for Code Injection and SSTI in six programming languages: Python, PHP, Java, Ruby, NodeJS and Elixir. Moreover, I will provide universal detection payloads, capable of quickly detecting even blind injections.

I will provide the full timeline of my research from finding the early breadcrumbs to the eventual conclusions. I will also explore the process of creating new payloads for programming languages and templates not mentioned in this research.

In this research I will show examples of practical applications of the new techniques and share potential areas of further research. All provided payloads can be used to detect and exploit vulnerabilities in real-life applications. Additionally, all provided payloads were added to the open-source tool SSTImap, which makes it easier to apply the results of this research to real-world targets.

Outline

  • Introduction
  • Breadcrumbs
    • Dust.JS
    • Twig (CVE-2022-23614)
    • JSONPath Plus (CVE-2025-1302)
    • expr-eval (CVE-2025-13204)
  • Error-Based SSTI
    • Python
    • PHP
    • Java
    • Ruby
    • NodeJS
    • Elixir
    • Generic Detection
    • Payload Development
  • Boolean Error-Based Blind SSTI
    • Error Detection
    • Python
    • PHP
    • Java
    • Ruby
    • NodeJS
    • Elixir
    • Generic Detection
    • Payload Development
  • Practical Application
    • expr-eval (CVE-2025-13204)
    • JSONPath Plus (CVE-2025-1302)
    • Twig (CVE-2022-23614)
    • Dust.JS
  • Conclusions
  • References

Introduction

Server-Side Template Injection vulnerabilities appear on dynamic websites using template engines for server-side rendering, when the untrusted user input is inserted into the template before it is processed by the template engine. A malicious actor can insert valid template syntax, which would be processed by a template engine during page rendering. Many template engines provide some form of code execution functionality, which often leads to Remote Code Execution (RCE) on the target server. This research is focused on template engines providing such capabilities in case of exploitation.

SSTI vulnerabilities have been known since 2015, and in that time a lot of payloads were discovered providing information exfiltration, filter bypasses and sandbox escaping. Despite that, most payloads are either rendering the result directly on the page or focusing on the fact of code execution itself, discarding the results produced by that code.

Rendered injection flow

Another well-known SSTI technique is Time-Based Blind, which involves adding a delay to the executed shell command. This technique allows determining the success of the injected code execution but requires guessing the payload for the OS command execution, which makes it harder to detect blind SSTI in an unknown to the researcher template engine.

Time-Based blind injection flow

SSTI vulnerability class and both known exploitation techniques were discovered in 2015 by James Kettle. Those techniques are described in great detail in his research “Server-Side Template Injection: RCE For The Modern Web App”. [^1] In ten years since then, no new exploitation techniques were documented. Only one detection technique was discovered in 2023, using polyglot payloads to test for multiple template engines at once. This technique was discovered by Maximilian Hildebrand and described in his research “Improving the Detection and Identification of Template Engines for Large-Scale Template Injection Scanning”. [^2] The technique is focused on determining the template engines using the minimal amount of requests, but only works for simple injection contexts.

Polyglot-Based detection flow

The majority of template engines based on interpreted programming languages, such as PHP, NodeJS and Python, directly allow evaluating the expressions of the corresponding programming languages. This capability allows us to use payloads for a broader Code Injection vulnerability category by wrapping it in the correct format of the template tag.

Code Injection can also occur without SSTI, when untrusted user input can reach eval() or a similar dangerous function. It is often considered that Code Injection exploitation is just programming in a corresponding language, so techniques and payloads are only documented for specific vulnerability examples, which require tailoring the code for the target application.

Lack of the more universal detection techniques for Code Injection and SSTI leads to the inefficiency of the black box scanning for blind code and template injections.

In this research, two new techniques will be provided for Code Injection and SSTI, as well as payloads for six programming languages and generic detection payloads. Provided techniques will extend the capabilities of the blind SSTI exploitation, as well as allowing blind Code Injection and SSTI scanning without guessing the programming language of the injected code.

Download Tool