gitex2026/AttackSurface/dist/testcases/owasp/sst-injection.yml
2026-04-24 19:18:37 +00:00

13 lines
273 B
YAML

payload:
- '<#assign ex = "freemarker.template.utility.Execute"?new()>${ ex("id")}'
- 'aaaa\u0027%2b#{16*8787}%2b\u0027bbb'
- '{{1337*1338}}'
encoder:
- Base64Flat
- URL
placeholder:
- URLPath
- URLParam
- HTMLForm
- HTMLMultipartForm
type: SST Injection