Vulnerability field guide
Server-Side Template Injection
When user input is stitched into a server-side template, the template engine becomes an interpreter for the attacker. Here is how a harmless-looking arithmetic probe escalates to full server compromise, and how to design the bug out entirely.
1 article 6 min total Overview to advanced techniques