Marko

Marko is another template engine, with a syntax very similar to HTML and JavaScript. Let's look at the following code:

<%
import os
x=os.popen('id').read()
%>
${x}

This code will also put an RCE risk in the application, it receives any parameter without validation and displays the result directly.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.16.49.108