App vulnerable to Server Side Template Injection built inside Ubuntu Image
893
What is Server Side Template Injection?
It is an attack that occurs when the user-controlled input is embedded into a server-side template, allowing users to inject template directives. This even allows an attacker to inject malicious template directives and possibly execute arbitrary code on the affected server.
Using the base image of Ubuntu a vulnerable app has been developed using Python and Flask.
Run the vulnerable app by executing: docker run -p 60:60 dockerbucket/ssti_env python ~/vulncode.py
Note: This application is built for testing an app vulnerable to SSTI and you can find the reference blog by accessing the link:
Content type
Image
Digest
Size
196.3 MB
Last updated
over 8 years ago
docker pull dockerbucket/ssti_env