Forum Discussion
QuickSloth
Bronze III
3 months agoStuck on “Server-Side Template Injection: Ep.2 – Identifying SSTI Vulnerabilities”
None of the three apps are “breaking” for me. For example the input of {{ dump(_SERVER) }} should return server information in at least one example. But nope.
QuickSloth
Bronze III
3 months ago> I think there's only one app using twig
I know. And I know which one is running twig. But I try all three for completeness.
I tried this on three different days. And I'm still not able to get anything to return the system information.
(Oops, meant this as a reply to netcat )