5089 | Remote Code Execution in AT&T |
RCE
SSTI
Components with known vulnerabilities |
AT&T |
Corben Leo (@hacker_) |
Bug Bounty | 2017-03-10 | 2023-06-13 |
4899 | RCE Vulnerabilite in Yahoo Subdomain! ( Yahoo! RCE via Spring Engine SSTI ) By tghawkins |
RCE |
Yahoo! / Verizon Media |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-01-05 | 2023-06-13 |
4676 | Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716] |
SSTI |
SEOmatic CMS plugin |
Sebastian (ha.cker.info) |
Bug Bounty | 2018-07-24 | 2023-06-13 |
4345 | Frappé Technologies ERPNext Server Side Template Injection |
SSTI |
ERPNext |
Brian Hyde (@0xHyde) |
Bug Bounty | 2019-01-23 | 2023-06-13 |
4220 | Handlebars template injection and RCE in a Shopify app |
SSTI
RCE |
Shopify |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2019-04-04 | 2023-06-13 |
3939 | Super Glamorous Recon with Intended Functionalities |
SSTI
XSS |
NA |
hateshape (@hateshaped) |
Bug Bounty | 2019-09-06 | 2023-06-13 |
3915 | RCE with Flask Jinja Template Injection |
SSTI
RCE |
NA |
AkShAy KaTkAr (@AkShAy KaTkAr) |
Bug Bounty | 2019-09-17 | 2023-06-13 |
3903 | Fuzzing {{7*7}} Till {{P1}} |
SSTI |
NA |
Verneet (@err0rrrrr) |
Bug Bounty | 2019-09-23 | 2023-06-13 |
3861 | How I hacked 50+ Companies in 6 hrs |
SSTI
RCE |
NA |
Vignesh C (@pwn_r00t) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3574 | Limited freemarker ssti to arbitrary liql query and manage lithium cms |
SSTI |
NA |
Mert (@mertistaken) |
Bug Bounty | 2020-03-30 | 2023-06-13 |
3025 | RCE via Server-Side Template Injection |
SSTI
RCE |
NA |
Gaurav Mishra (@gmishra010) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
2992 | SSTI to Local File Read |
SSTI
LFI |
NA |
Demon (@R29k_) |
Bug Bounty | 2020-12-02 | 2023-06-13 |
2953 | SSTI in Google Maps |
SSTI |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-22 | 2023-06-13 |
2768 | Stealing user passwords through a VPN’s SSO |
Open redirect
SSTI |
NA |
Alain Mowat (@plopz0r) |
Bug Bounty | 2021-02-25 | 2023-06-13 |
2711 | Abusing Data Protection Laws For D0xing & Account Takeovers |
SSTI
Account takeover |
NA |
Hx01 (@Hxzeroone) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2389 | How I Found Multiple Bugs On FaceBook In 1 Month And a Part For My Methodology & Tools |
SSTI
SQL injection
Authentication bypass
Privilege escalation
Reflected XSS |
Meta / Facebook |
Orwa Atyat (@GodfatherOrwa) |
Bug Bounty | 2021-07-23 | 2023-06-13 |
1708 | iTop – Template Injection inside customer Portal |
SSTI
RCE |
Combodo (iTop) |
Markus Krell (@MarkusKrell) |
Bug Bounty | 2022-03-21 | 2023-06-13 |
1600 | EJS, Server side template injection RCE (CVE-2022-29078) - writeup |
SSTI
RCE |
ejs
NetApp |
Eslam Salem (@net_code) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1210 | RCE on Spip and Root-Me, v2! |
RCE
SSTI
DNS rebinding
XSS
Code injection
Unrestricted file upload |
SPIP |
Laluka (@TheLaluka) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1036 | Escalating SSTI to Reflected XSS using curly braces {} |
SSTI
XSS |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
729 | Bug Writeup: RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass |
SSTI
RCE
WAF bypass |
GitHub |
Peter M (@h1pmnh) |
Bug Bounty | 2022-12-04 | 2023-06-13 |
697 | Doing it the researcher’s way: How I Managed to Get SSTI (Server Side Template Injection) which lead to arbitrary file reading on One of the Leading Payment Systems in Asia |
SSTI
WAF bypass |
NA |
JzeeRx |
Bug Bounty | 2022-12-13 | 2023-06-13 |
532 | Froxlor v2.0.6 Remote Command Execution (CVE-2023-0315) |
RCE
Arbitrary file write
SSTI
Security code review |
Froxlor |
Askar (@mohammadaskar2) |
Bug Bounty | 2023-01-29 | 2023-06-13 |
485 | [CVE-2023-22855] Kardex MLOG - Insecure path join to RCE via SSTI |
RCE
SSTI
Security code review |
NA |
Patrick Hener (@C1sc01) |
Bug Bounty | 2023-02-07 | 2023-06-13 |
282 | SSTI leads to RCE on PyroCMS |
SSTI
RCE |
PyroCMS |
cupc4k3 |
Bug Bounty | 2023-03-20 | 2023-06-13 |